summaryrefslogtreecommitdiffstats
path: root/apps/theming
diff options
context:
space:
mode:
authorJulius Härtl <jus@bitgrid.net>2019-11-27 20:26:57 +0100
committerJulius Härtl <jus@bitgrid.net>2019-11-27 20:26:57 +0100
commit9691360f6ec2224dd6508d32cc095e320bb27bd5 (patch)
tree3e316b70df61fed37299149ed9e9e98ded6ef067 /apps/theming
parentfa1b23b67aec1fcc8f6e8093fce184a308aed647 (diff)
downloadnextcloud-server-9691360f6ec2224dd6508d32cc095e320bb27bd5.tar.gz
nextcloud-server-9691360f6ec2224dd6508d32cc095e320bb27bd5.zip
Allow inline styles for theming images
Signed-off-by: Julius Härtl <jus@bitgrid.net>
Diffstat (limited to 'apps/theming')
-rw-r--r--apps/theming/lib/Controller/ThemingController.php3
1 files changed, 3 insertions, 0 deletions
diff --git a/apps/theming/lib/Controller/ThemingController.php b/apps/theming/lib/Controller/ThemingController.php
index 25c2273279e..34ea22207ce 100644
--- a/apps/theming/lib/Controller/ThemingController.php
+++ b/apps/theming/lib/Controller/ThemingController.php
@@ -379,6 +379,9 @@ class ThemingController extends Controller {
}
$response = new FileDisplayResponse($file);
+ $csp = new Http\ContentSecurityPolicy();
+ $csp->allowInlineStyle();
+ $response->setContentSecurityPolicy($csp);
$response->cacheFor(3600);
$response->addHeader('Content-Type', $this->config->getAppValue($this->appName, $key . 'Mime', ''));
$response->addHeader('Content-Disposition', 'attachment; filename="' . $key . '"');