aboutsummaryrefslogtreecommitdiffstats
path: root/lib/public
diff options
context:
space:
mode:
authorRoeland Jago Douma <roeland@famdouma.nl>2018-07-11 21:12:36 +0200
committerRoeland Jago Douma <roeland@famdouma.nl>2018-07-11 21:12:36 +0200
commitc21cee248cc470a99aca4351cdf8b71a3bba470e (patch)
tree9831d9471e6bc607042f53e75155461c760761f7 /lib/public
parentd9aa5ed96df3a641e1e0a62675a295a22f54c4bb (diff)
downloadnextcloud-server-c21cee248cc470a99aca4351cdf8b71a3bba470e.tar.gz
nextcloud-server-c21cee248cc470a99aca4351cdf8b71a3bba470e.zip
Disallow eval on the StrictEvalCSP
Signed-off-by: Roeland Jago Douma <roeland@famdouma.nl>
Diffstat (limited to 'lib/public')
-rw-r--r--lib/public/AppFramework/Http/StrictEvalContentSecurityPolicy.php2
1 files changed, 1 insertions, 1 deletions
diff --git a/lib/public/AppFramework/Http/StrictEvalContentSecurityPolicy.php b/lib/public/AppFramework/Http/StrictEvalContentSecurityPolicy.php
index c1d6093d880..b95d2c65e50 100644
--- a/lib/public/AppFramework/Http/StrictEvalContentSecurityPolicy.php
+++ b/lib/public/AppFramework/Http/StrictEvalContentSecurityPolicy.php
@@ -46,6 +46,6 @@ class StrictEvalContentSecurityPolicy extends ContentSecurityPolicy {
* @since 14.0.0
*/
public function __construct() {
- $this->inlineStyleAllowed = false;
+ $this->evalScriptAllowed = false;
}
}