diff --git a/next.config.ts b/next.config.ts index 8e424f8341..41aaadaa9d 100644 --- a/next.config.ts +++ b/next.config.ts @@ -15,7 +15,7 @@ const securityHeaders = [ key: "Content-Security-Policy", value: [ "default-src 'self'", - "script-src 'self' https://challenges.cloudflare.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/", + "script-src 'self' 'unsafe-inline' https://challenges.cloudflare.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://static.cloudflareinsights.com", "style-src 'self' 'unsafe-inline'", "img-src 'self' data: blob: https:", "frame-src 'self' https://challenges.cloudflare.com https://www.google.com/recaptcha/", diff --git a/src/lib/auth.ts b/src/lib/auth.ts index 40cc97ed18..1dcce8af94 100644 --- a/src/lib/auth.ts +++ b/src/lib/auth.ts @@ -42,7 +42,7 @@ async function verify2faCode(userId: number, code: string): Promise { } export const { handlers, signIn, signOut, auth } = NextAuth({ - trustHost: process.env.NODE_ENV === "development", + trustHost: true, session: { strategy: "jwt", maxAge: 24 * 60 * 60 }, pages: { signIn: "/login" }, providers: [