diff --git a/.htaccess b/.htaccess index 43c8ea2206..2a4c8dfe5b 100644 --- a/.htaccess +++ b/.htaccess @@ -41,8 +41,8 @@ RewriteEngine on - RewriteCond %{HTTP_USER_AGENT} DavClnt - RewriteRule ^$ /remote.php/webdav/ [L,R=302] + RewriteCond %{HTTP_USER_AGENT} DavClnt + RewriteRule ^$ /remote.php/webdav/ [L,R=302] RewriteRule .* - [env=HTTP_AUTHORIZATION:%{HTTP:Authorization}] RewriteRule ^\.well-known/host-meta /public.php?service=host-meta [QSA,L] RewriteRule ^\.well-known/host-meta\.json /public.php?service=host-meta-json [QSA,L] diff --git a/lib/private/legacy/response.php b/lib/private/legacy/response.php index 73bafe70c3..46d90816db 100644 --- a/lib/private/legacy/response.php +++ b/lib/private/legacy/response.php @@ -89,7 +89,7 @@ class OC_Response { . 'frame-src *; ' . 'img-src * data: blob:; ' . 'font-src \'self\' data:; ' - . 'media-src *; ' + . 'media-src *; ' . 'connect-src *; ' . 'object-src \'none\'; ' . 'base-uri \'self\'; ';