diff options
author | Roeland Jago Douma <rullzer@users.noreply.github.com> | 2017-03-17 08:39:02 +0100 |
---|---|---|
committer | GitHub <noreply@github.com> | 2017-03-17 08:39:02 +0100 |
commit | 9915aa6d9c5f5cf4ebac0b6bc0df0c16ca215c70 (patch) | |
tree | d8625ad9a7b6508d15fcc3c8a1005ddcb07f94ab /tests/lib/AppFramework/Http/ResponseTest.php | |
parent | 7a3acff7824ad8a83f6fcec7915a8a88b0a7d4df (diff) | |
parent | 9e957d0ac900b845468a42ed1b2192d5b10b5753 (diff) | |
download | nextcloud-server-9915aa6d9c5f5cf4ebac0b6bc0df0c16ca215c70.tar.gz nextcloud-server-9915aa6d9c5f5cf4ebac0b6bc0df0c16ca215c70.zip |
Merge pull request #3870 from nextcloud/add-base-uri-to-csp-policy
Add base-uri to CSP policy
Diffstat (limited to 'tests/lib/AppFramework/Http/ResponseTest.php')
-rw-r--r-- | tests/lib/AppFramework/Http/ResponseTest.php | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/tests/lib/AppFramework/Http/ResponseTest.php b/tests/lib/AppFramework/Http/ResponseTest.php index 3ed946dc6ca..0331bb42c01 100644 --- a/tests/lib/AppFramework/Http/ResponseTest.php +++ b/tests/lib/AppFramework/Http/ResponseTest.php @@ -58,14 +58,14 @@ class ResponseTest extends \Test\TestCase { $this->childResponse->setHeaders($expected); $headers = $this->childResponse->getHeaders(); - $expected['Content-Security-Policy'] = "default-src 'none';script-src 'self' 'unsafe-eval';style-src 'self' 'unsafe-inline';img-src 'self' data: blob:;font-src 'self';connect-src 'self';media-src 'self'"; + $expected['Content-Security-Policy'] = "default-src 'none';base-uri 'none';script-src 'self' 'unsafe-eval';style-src 'self' 'unsafe-inline';img-src 'self' data: blob:;font-src 'self';connect-src 'self';media-src 'self'"; $this->assertEquals($expected, $headers); } public function testOverwriteCsp() { $expected = [ - 'Content-Security-Policy' => "default-src 'none';script-src 'self' 'unsafe-inline' 'unsafe-eval';style-src 'self' 'unsafe-inline';img-src 'self';font-src 'self';connect-src 'self';media-src 'self'", + 'Content-Security-Policy' => "default-src 'none';base-uri 'none';script-src 'self' 'unsafe-inline' 'unsafe-eval';style-src 'self' 'unsafe-inline';img-src 'self';font-src 'self';connect-src 'self';media-src 'self'", ]; $policy = new Http\ContentSecurityPolicy(); $policy->allowInlineScript(true); |