Merge pull request #15016 from nextcloud/enh/no-eval-default-response
Forbid eval on legacy responses
This commit is contained in:
commit
1416ef65e4
|
@ -84,7 +84,7 @@ class OC_Response {
|
||||||
* @see \OCP\AppFramework\Http\Response::getHeaders
|
* @see \OCP\AppFramework\Http\Response::getHeaders
|
||||||
*/
|
*/
|
||||||
$policy = 'default-src \'self\'; '
|
$policy = 'default-src \'self\'; '
|
||||||
. 'script-src \'self\' \'unsafe-eval\' \'nonce-'.\OC::$server->getContentSecurityPolicyNonceManager()->getNonce().'\'; '
|
. 'script-src \'self\' \'nonce-'.\OC::$server->getContentSecurityPolicyNonceManager()->getNonce().'\'; '
|
||||||
. 'style-src \'self\' \'unsafe-inline\'; '
|
. 'style-src \'self\' \'unsafe-inline\'; '
|
||||||
. 'frame-src *; '
|
. 'frame-src *; '
|
||||||
. 'img-src * data: blob:; '
|
. 'img-src * data: blob:; '
|
||||||
|
|
Loading…
Reference in New Issue