diff --git a/lib/private/legacy/response.php b/lib/private/legacy/response.php index 88725d5e30..69c84e2df6 100644 --- a/lib/private/legacy/response.php +++ b/lib/private/legacy/response.php @@ -247,7 +247,7 @@ class OC_Response { * @see \OCP\AppFramework\Http\Response::getHeaders */ $policy = 'default-src \'self\'; ' - . 'script-src \'self\' \'unsafe-eval\'; ' + . 'script-src \'self\' \'unsafe-eval\' \'nonce-'.\OC::$server->getContentSecurityPolicyNonceManager()->getNonce().'\'; ' . 'style-src \'self\' \'unsafe-inline\'; ' . 'frame-src *; ' . 'img-src * data: blob:; '