Browse Source

Merge pull request #15016 from nextcloud/enh/no-eval-default-response

Forbid eval on legacy responses
pull/15027/head
Morris Jobke 7 years ago
committed by GitHub
parent
commit
1416ef65e4
No known key found for this signature in database GPG Key ID: 4AEE18F83AFDEB23
  1. 2
      lib/private/legacy/response.php

2
lib/private/legacy/response.php

@ -84,7 +84,7 @@ class OC_Response {
* @see \OCP\AppFramework\Http\Response::getHeaders
*/
$policy = 'default-src \'self\'; '
. 'script-src \'self\' \'unsafe-eval\' \'nonce-'.\OC::$server->getContentSecurityPolicyNonceManager()->getNonce().'\'; '
. 'script-src \'self\' \'nonce-'.\OC::$server->getContentSecurityPolicyNonceManager()->getNonce().'\'; '
. 'style-src \'self\' \'unsafe-inline\'; '
. 'frame-src *; '
. 'img-src * data: blob:; '

Loading…
Cancel
Save