Browse Source
Merge pull request #15016 from nextcloud/enh/no-eval-default-response
Forbid eval on legacy responses
pull/15027/head
Morris Jobke
7 years ago
committed by
GitHub
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with
1 additions and
1 deletions
-
lib/private/legacy/response.php
|
|
|
@ -84,7 +84,7 @@ class OC_Response { |
|
|
|
* @see \OCP\AppFramework\Http\Response::getHeaders |
|
|
|
*/ |
|
|
|
$policy = 'default-src \'self\'; ' |
|
|
|
. 'script-src \'self\' \'unsafe-eval\' \'nonce-'.\OC::$server->getContentSecurityPolicyNonceManager()->getNonce().'\'; ' |
|
|
|
. 'script-src \'self\' \'nonce-'.\OC::$server->getContentSecurityPolicyNonceManager()->getNonce().'\'; ' |
|
|
|
. 'style-src \'self\' \'unsafe-inline\'; ' |
|
|
|
. 'frame-src *; ' |
|
|
|
. 'img-src * data: blob:; ' |
|
|
|
|