Merge pull request #14724 from nextcloud/enh/nonce_for_iframes

CSP: set nonce for iframes
pull/14614/head^2
Morris Jobke 7 years ago committed by GitHub
commit 458359563b
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
  1. 6
      lib/public/AppFramework/Http/EmptyContentSecurityPolicy.php

@ -468,7 +468,11 @@ class EmptyContentSecurityPolicy {
}
if(!empty($this->allowedFrameDomains)) {
$policy .= 'frame-src ' . implode(' ', $this->allowedFrameDomains);
$policy .= 'frame-src ';
if(is_string($this->useJsNonce)) {
$policy .= '\'nonce-' . base64_encode($this->useJsNonce) . '\' ';
}
$policy .= implode(' ', $this->allowedFrameDomains);
$policy .= ';';
}

Loading…
Cancel
Save