Skip to content

Commit 1416ef6

Browse files
authored
Merge pull request #15016 from nextcloud/enh/no-eval-default-response
Forbid eval on legacy responses
2 parents ec4b158 + 3b1e164 commit 1416ef6

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

lib/private/legacy/response.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -84,7 +84,7 @@ public static function addSecurityHeaders() {
8484
* @see \OCP\AppFramework\Http\Response::getHeaders
8585
*/
8686
$policy = 'default-src \'self\'; '
87-
. 'script-src \'self\' \'unsafe-eval\' \'nonce-'.\OC::$server->getContentSecurityPolicyNonceManager()->getNonce().'\'; '
87+
. 'script-src \'self\' \'nonce-'.\OC::$server->getContentSecurityPolicyNonceManager()->getNonce().'\'; '
8888
. 'style-src \'self\' \'unsafe-inline\'; '
8989
. 'frame-src *; '
9090
. 'img-src * data: blob:; '

0 commit comments

Comments
 (0)