0
0
Fork 1
mirror of https://mau.dev/maunium/synapse.git synced 2024-10-04 15:39:01 +02:00

Add quotes and be explicity about script-src

This commit is contained in:
Erik Johnston 2016-09-05 17:35:01 +01:00
parent 662b031a30
commit d51b8a1674

View file

@ -47,7 +47,8 @@ class DownloadResource(Resource):
def _async_render_GET(self, request):
request.setHeader(
"Content-Security-Policy",
"default-src none;"
"default-src 'none';"
" script-src 'none';"
" plugin-types application/pdf;"
" style-src 'unsafe-inline';"
" object-src 'self';"