tighten CSP for blob/file host: remove allow-same-origin
This commit is contained in:
parent
27a985a4bc
commit
ea38f8233f
@ -89,7 +89,7 @@ module.exports = function (sbot, checkout_dir) {
|
|||||||
"connect-src 'self'; "+
|
"connect-src 'self'; "+
|
||||||
"object-src 'none'; "+
|
"object-src 'none'; "+
|
||||||
"frame-src 'none'; "+
|
"frame-src 'none'; "+
|
||||||
"sandbox allow-same-origin allow-scripts"
|
"sandbox allow-scripts"
|
||||||
)
|
)
|
||||||
|
|
||||||
if (req.url.slice(-7) != '.sha256' && opts.serveFiles) {
|
if (req.url.slice(-7) != '.sha256' && opts.serveFiles) {
|
||||||
|
Loading…
Reference in New Issue
Block a user