diff --git a/packages/familie-backend/src/headers.ts b/packages/familie-backend/src/headers.ts index cc7f8653..1f64ab77 100644 --- a/packages/familie-backend/src/headers.ts +++ b/packages/familie-backend/src/headers.ts @@ -5,8 +5,10 @@ const fontSource = 'https://fonts.gstatic.com'; const navFontSource = 'https://cdn.nav.no'; const amplitude = 'https://amplitude.nav.no'; const sentry = 'https://sentry.gc.nav.no'; +const navTelemetry = 'https://telemetry.nav.no'; +const navTelemetryDev = 'https://telemetry.ekstern.dev.nav.no'; -const cspString = `default-src 'self' data: ${amplitude} ${sentry}; style-src 'self' ${styleSource} data: 'unsafe-inline'; font-src 'self' ${fontSource} ${navFontSource} data:; frame-src 'self' blob:;`; +const cspString = `default-src 'self' data: ${amplitude} ${sentry} ${navTelemetry} ${navTelemetryDev}; style-src 'self' ${styleSource} data: 'unsafe-inline'; font-src 'self' ${fontSource} ${navFontSource} data:; frame-src 'self' blob:;`; const setup = (app: Express) => { app.disable('x-powered-by');