diff options
author | Lukas Reschke <lukas@owncloud.com> | 2015-09-29 14:18:12 +0200 |
---|---|---|
committer | Lukas Reschke <lukas@owncloud.com> | 2015-09-29 14:27:35 +0200 |
commit | e735a9915cec6a26f7f6d89100fef383c563fd0d (patch) | |
tree | f9ddbb5ce4f81d319a8c399a38be4f21d16bb58f /tests/lib/appframework/controller | |
parent | c061b3e44b56c5cd89aeb4a6bad4673155e7ee9e (diff) | |
download | nextcloud-server-e735a9915cec6a26f7f6d89100fef383c563fd0d.tar.gz nextcloud-server-e735a9915cec6a26f7f6d89100fef383c563fd0d.zip |
Add blob: scheme to default CSP policy
Fixes https://github.com/owncloud/core/issues/19438
Diffstat (limited to 'tests/lib/appframework/controller')
-rw-r--r-- | tests/lib/appframework/controller/ControllerTest.php | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/tests/lib/appframework/controller/ControllerTest.php b/tests/lib/appframework/controller/ControllerTest.php index 243014a91a7..c847525c263 100644 --- a/tests/lib/appframework/controller/ControllerTest.php +++ b/tests/lib/appframework/controller/ControllerTest.php @@ -178,7 +178,7 @@ class ControllerTest extends \Test\TestCase { 'test' => 'something', 'Cache-Control' => 'no-cache, must-revalidate', 'Content-Type' => 'application/json; charset=utf-8', - 'Content-Security-Policy' => "default-src 'none';script-src 'self' 'unsafe-eval';style-src 'self' 'unsafe-inline';img-src 'self' data:;font-src 'self';connect-src 'self';media-src 'self'", + 'Content-Security-Policy' => "default-src 'none';script-src 'self' 'unsafe-eval';style-src 'self' 'unsafe-inline';img-src 'self' data: blob:;font-src 'self';connect-src 'self';media-src 'self'", ]; $response = $this->controller->customDataResponse(array('hi')); |