summaryrefslogtreecommitdiffstats
path: root/lib
diff options
context:
space:
mode:
authorRoeland Jago Douma <roeland@famdouma.nl>2019-04-09 09:49:33 +0200
committerRoeland Jago Douma <roeland@famdouma.nl>2019-04-09 09:58:23 +0200
commit3b1e16458d59ea53b170d6099df3454d0590e87a (patch)
tree7ec58c6cc6257a4cc96b22d4672dde3659e9eb3a /lib
parent5d360bd16f345e395f7650998e8ee4a5d252c2b5 (diff)
downloadnextcloud-server-3b1e16458d59ea53b170d6099df3454d0590e87a.tar.gz
nextcloud-server-3b1e16458d59ea53b170d6099df3454d0590e87a.zip
Forbid eval on legacy responses
Signed-off-by: Roeland Jago Douma <roeland@famdouma.nl>
Diffstat (limited to 'lib')
-rw-r--r--lib/private/legacy/response.php2
1 files changed, 1 insertions, 1 deletions
diff --git a/lib/private/legacy/response.php b/lib/private/legacy/response.php
index bfee5aadb4d..361a085c0c0 100644
--- a/lib/private/legacy/response.php
+++ b/lib/private/legacy/response.php
@@ -84,7 +84,7 @@ class OC_Response {
* @see \OCP\AppFramework\Http\Response::getHeaders
*/
$policy = 'default-src \'self\'; '
- . 'script-src \'self\' \'unsafe-eval\' \'nonce-'.\OC::$server->getContentSecurityPolicyNonceManager()->getNonce().'\'; '
+ . 'script-src \'self\' \'nonce-'.\OC::$server->getContentSecurityPolicyNonceManager()->getNonce().'\'; '
. 'style-src \'self\' \'unsafe-inline\'; '
. 'frame-src *; '
. 'img-src * data: blob:; '