aboutsummaryrefslogtreecommitdiffstats
path: root/lib/private/legacy
diff options
context:
space:
mode:
authorFerdinand Thiessen <opensource@fthiessen.de>2024-08-01 23:06:55 +0200
committerFerdinand Thiessen <opensource@fthiessen.de>2024-08-13 10:32:44 +0200
commit2916e5df7e08fc588e752beaf486d907112a34ee (patch)
tree968c83adcd9a70717bda5d1d1a5e06f23a158097 /lib/private/legacy
parent009761be58c4485f29a8d3382e51fb4e1bfbeec4 (diff)
downloadnextcloud-server-2916e5df7e08fc588e752beaf486d907112a34ee.tar.gz
nextcloud-server-2916e5df7e08fc588e752beaf486d907112a34ee.zip
feat: Provide CSP nonce as `<meta>` element
This way we use the CSP nonce for dynamically loaded scripts. Important to notice: The CSP nonce must NOT be injected in `content` as this can lead to value exfiltration using e.g. side-channel attacts (CSS selectors). Signed-off-by: Ferdinand Thiessen <opensource@fthiessen.de>
Diffstat (limited to 'lib/private/legacy')
-rw-r--r--lib/private/legacy/OC_Template.php9
1 files changed, 8 insertions, 1 deletions
diff --git a/lib/private/legacy/OC_Template.php b/lib/private/legacy/OC_Template.php
index 5caa733b115..e3e9a7abc5f 100644
--- a/lib/private/legacy/OC_Template.php
+++ b/lib/private/legacy/OC_Template.php
@@ -43,6 +43,7 @@ class OC_Template extends \OC\Template\Base {
$theme = OC_Util::getTheme();
$requestToken = (OC::$server->getSession() && $registerCall) ? \OCP\Util::callRegister() : '';
+ $cspNonce = \OCP\Server::get(\OC\Security\CSP\ContentSecurityPolicyNonceManager::class)->getNonce();
$parts = explode('/', $app); // fix translation when app is something like core/lostpassword
$l10n = \OC::$server->getL10N($parts[0]);
@@ -56,7 +57,13 @@ class OC_Template extends \OC\Template\Base {
$this->path = $path;
$this->app = $app;
- parent::__construct($template, $requestToken, $l10n, $themeDefaults);
+ parent::__construct(
+ $template,
+ $requestToken,
+ $l10n,
+ $themeDefaults,
+ $cspNonce,
+ );
}