diff options
author | Roeland Jago Douma <roeland@famdouma.nl> | 2018-07-11 21:12:36 +0200 |
---|---|---|
committer | Roeland Jago Douma <roeland@famdouma.nl> | 2018-07-11 21:12:36 +0200 |
commit | c21cee248cc470a99aca4351cdf8b71a3bba470e (patch) | |
tree | 9831d9471e6bc607042f53e75155461c760761f7 /lib/public | |
parent | d9aa5ed96df3a641e1e0a62675a295a22f54c4bb (diff) | |
download | nextcloud-server-c21cee248cc470a99aca4351cdf8b71a3bba470e.tar.gz nextcloud-server-c21cee248cc470a99aca4351cdf8b71a3bba470e.zip |
Disallow eval on the StrictEvalCSP
Signed-off-by: Roeland Jago Douma <roeland@famdouma.nl>
Diffstat (limited to 'lib/public')
-rw-r--r-- | lib/public/AppFramework/Http/StrictEvalContentSecurityPolicy.php | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/lib/public/AppFramework/Http/StrictEvalContentSecurityPolicy.php b/lib/public/AppFramework/Http/StrictEvalContentSecurityPolicy.php index c1d6093d880..b95d2c65e50 100644 --- a/lib/public/AppFramework/Http/StrictEvalContentSecurityPolicy.php +++ b/lib/public/AppFramework/Http/StrictEvalContentSecurityPolicy.php @@ -46,6 +46,6 @@ class StrictEvalContentSecurityPolicy extends ContentSecurityPolicy { * @since 14.0.0 */ public function __construct() { - $this->inlineStyleAllowed = false; + $this->evalScriptAllowed = false; } } |