Add stricter CSPs
* Deprecate our default CSP
* Add strict CSP that is always our strictest setting
* Add strict eval CSP (disable unsafe-eval)
* Add strict inline CSP (disables inline styles)
This is just to move forward and have a incremental improvement of our
CSP
Signed-off-by:
Roeland Jago Douma <roeland@famdouma.nl>
Showing
- lib/composer/composer/autoload_classmap.php 3 additions, 0 deletionslib/composer/composer/autoload_classmap.php
- lib/composer/composer/autoload_static.php 3 additions, 0 deletionslib/composer/composer/autoload_static.php
- lib/public/AppFramework/Http/ContentSecurityPolicy.php 5 additions, 2 deletionslib/public/AppFramework/Http/ContentSecurityPolicy.php
- lib/public/AppFramework/Http/StrictContentSecurityPolicy.php 85 additions, 0 deletionslib/public/AppFramework/Http/StrictContentSecurityPolicy.php
- lib/public/AppFramework/Http/StrictEvalContentSecurityPolicy.php 51 additions, 0 deletions...lic/AppFramework/Http/StrictEvalContentSecurityPolicy.php
- lib/public/AppFramework/Http/StrictInlineContentSecurityPolicy.php 51 additions, 0 deletions...c/AppFramework/Http/StrictInlineContentSecurityPolicy.php
Loading
Please register or sign in to comment