diff --git a/portal-frontend/nginx.conf b/portal-frontend/nginx.conf index 45a82c19a0..8db9efc810 100644 --- a/portal-frontend/nginx.conf +++ b/portal-frontend/nginx.conf @@ -19,7 +19,7 @@ http { add_header 'X-XSS-Protection' '1; mode=block'; add_header 'Strict-Transport-Security' 'max-age=31536000; includeSubDomains; preload'; add_header 'Cache-control' 'no-cache'; - add_header 'Content-Security-Policy' "default-src 'self';img-src 'self';style-src 'unsafe-inline' 'self';connect-src $ENABLED_CONNECT_SRC; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com; base-uri 'self'; object-src 'none';"; + add_header 'Content-Security-Policy' "default-src 'self';img-src 'self';style-src 'unsafe-inline' 'self';connect-src $ENABLED_CONNECT_SRC; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com; base-uri 'self'; object-src https://nrs.objectstore.gov.bc.ca; frame-src https://nrs.objectstore.gov.bc.ca;"; add_header 'Permissions-Policy' 'camera=(), geolocation=(), microphone=()'; add_header 'Referrer-Policy' 'same-origin'; diff --git a/services/templates/emails/submitted-to-alc/noi-applicant.template.ts b/services/templates/emails/submitted-to-alc/noi-applicant.template.ts index 4426caa3dd..0601101c0a 100644 --- a/services/templates/emails/submitted-to-alc/noi-applicant.template.ts +++ b/services/templates/emails/submitted-to-alc/noi-applicant.template.ts @@ -34,7 +34,7 @@ const template = ` - Application Type + NOI Type ALC Portion of Fee ${noiFees