aboutsummaryrefslogtreecommitdiffstats
path: root/lib
diff options
context:
space:
mode:
authorRoeland Jago Douma <rullzer@users.noreply.github.com>2017-03-17 08:39:02 +0100
committerGitHub <noreply@github.com>2017-03-17 08:39:02 +0100
commit9915aa6d9c5f5cf4ebac0b6bc0df0c16ca215c70 (patch)
treed8625ad9a7b6508d15fcc3c8a1005ddcb07f94ab /lib
parent7a3acff7824ad8a83f6fcec7915a8a88b0a7d4df (diff)
parent9e957d0ac900b845468a42ed1b2192d5b10b5753 (diff)
downloadnextcloud-server-9915aa6d9c5f5cf4ebac0b6bc0df0c16ca215c70.tar.gz
nextcloud-server-9915aa6d9c5f5cf4ebac0b6bc0df0c16ca215c70.zip
Merge pull request #3870 from nextcloud/add-base-uri-to-csp-policy
Add base-uri to CSP policy
Diffstat (limited to 'lib')
-rw-r--r--lib/public/AppFramework/Http/EmptyContentSecurityPolicy.php1
1 files changed, 1 insertions, 0 deletions
diff --git a/lib/public/AppFramework/Http/EmptyContentSecurityPolicy.php b/lib/public/AppFramework/Http/EmptyContentSecurityPolicy.php
index 90ba47a2f3f..c53b5b2146c 100644
--- a/lib/public/AppFramework/Http/EmptyContentSecurityPolicy.php
+++ b/lib/public/AppFramework/Http/EmptyContentSecurityPolicy.php
@@ -335,6 +335,7 @@ class EmptyContentSecurityPolicy {
*/
public function buildPolicy() {
$policy = "default-src 'none';";
+ $policy .= "base-uri 'none';";
if(!empty($this->allowedScriptDomains) || $this->inlineScriptAllowed || $this->evalScriptAllowed) {
$policy .= 'script-src ';