Forbid eval on legacy responsestags/v16.0.0RC1
@@ -84,7 +84,7 @@ class OC_Response { | |||
* @see \OCP\AppFramework\Http\Response::getHeaders | |||
*/ | |||
$policy = 'default-src \'self\'; ' | |||
. 'script-src \'self\' \'unsafe-eval\' \'nonce-'.\OC::$server->getContentSecurityPolicyNonceManager()->getNonce().'\'; ' | |||
. 'script-src \'self\' \'nonce-'.\OC::$server->getContentSecurityPolicyNonceManager()->getNonce().'\'; ' | |||
. 'style-src \'self\' \'unsafe-inline\'; ' | |||
. 'frame-src *; ' | |||
. 'img-src * data: blob:; ' |