From 3b1e16458d59ea53b170d6099df3454d0590e87a Mon Sep 17 00:00:00 2001 From: Roeland Jago Douma <roeland@famdouma.nl> Date: Tue, 9 Apr 2019 09:49:33 +0200 Subject: [PATCH] Forbid eval on legacy responses Signed-off-by: Roeland Jago Douma <roeland@famdouma.nl> --- lib/private/legacy/response.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/private/legacy/response.php b/lib/private/legacy/response.php index bfee5aadb4d..361a085c0c0 100644 --- a/lib/private/legacy/response.php +++ b/lib/private/legacy/response.php @@ -84,7 +84,7 @@ class OC_Response { * @see \OCP\AppFramework\Http\Response::getHeaders */ $policy = 'default-src \'self\'; ' - . 'script-src \'self\' \'unsafe-eval\' \'nonce-'.\OC::$server->getContentSecurityPolicyNonceManager()->getNonce().'\'; ' + . 'script-src \'self\' \'nonce-'.\OC::$server->getContentSecurityPolicyNonceManager()->getNonce().'\'; ' . 'style-src \'self\' \'unsafe-inline\'; ' . 'frame-src *; ' . 'img-src * data: blob:; ' -- GitLab