Commit Graph

40 Commits (2bdc97741cd42843f85750421cba032942d860ed)

Author SHA1 Message Date
Ferdinand Thiessen 2916e5df7e
feat: Provide CSP nonce as `<meta>` element 1 year ago
Ferdinand Thiessen 86f01a3358
fix: Make sure CSP nonce is not double base64 encoded 1 year ago
Andy Scherzinger dae7c159f7
chore: Add SPDX header 2 years ago
Ferdinand Thiessen 5a513c924f
fix(CSP): Add CSP nonce by default and convert `browserSupportsCspV3` to blocklist 2 years ago
Julius Härtl 02d6d3f5b1
fix: Add edge as supported user agent for CSPv3 nonces 2 years ago
Ferdinand Thiessen 7df9eb3351 feat(ContentSecurityPolicy): Allow to set `strict-dynamic` on `script-src-elem` only 2 years ago
Faraz Samapoor f313ca92e7 Refactors lib/private/Security. 2 years ago
Daniel Calviño Sánchez 41f2d912d2 Allow "wasm-unsafe-eval" in CSP 2 years ago
Carl Schwan ca3cd5a625 Fix detection of firefox in ContentSecurityPolicyNonceManager 4 years ago
Vincent Petry 18c013d8fc
Add CSP policy merge priority for booleans 4 years ago
Julius Härtl bd03dd37be
Allow to set a strict-dynamic CSP through the API 4 years ago
John Molakvoæ (skjnldsv) 215aef3cbd
Update php licenses 5 years ago
Christoph Wurst 2a054e6c04
Update the license headers for Nextcloud 20 5 years ago
Morris Jobke c0be7e329f
Prefer typed event over string based ones 5 years ago
Christoph Wurst cb057829f7
Update license headers for 19 6 years ago
Christoph Wurst caff1023ea
Format control structures, classes, methods and function 6 years ago
Christoph Wurst 1a9330cd69
Update the license headers for Nextcloud 19 6 years ago
Pavel Krasikov f11dee9bc4 fix safari useragent for versions with 3 digits 6 years ago
Christoph Wurst 5bf3d1bb38
Update license headers 6 years ago
Roeland Jago Douma 68748d4f85
Some php-cs fixes 6 years ago
Roeland Jago Douma f94ee72507
Add form-action CSP element 7 years ago
Roeland Jago Douma 417fbb5d60
setting unsafe-eval is deprecated 7 years ago
Sam Bull ea935f65fd
Add support for CSP_NONCE server variable 7 years ago
Roeland Jago Douma 5ac857bcdc
Add an event to edit the CSP 7 years ago
Roeland Jago Douma 0fdc65a15c
Add nonce for Safari 12+ 7 years ago
Roeland Jago Douma 579822b6a5
Add report-uri to CSP 7 years ago
Roeland Jago Douma 8354c50911
Deprecate the childSrc functions 7 years ago
Roeland Jago Douma c8fe4b4fc8
Add workerSrc to CSP 7 years ago
Roeland Jago Douma 4ed9b74a6b
Make OC\Security\CSP strict 8 years ago
Morris Jobke 0eebff152a
Update license headers 8 years ago
Thomas Citharel ecf347bd1a Add CSP frame-ancestors support 8 years ago
Lukas Reschke 7d221ff8f4
Safari CSPv3 support is sub-par 9 years ago
Joas Schilling c20ab0049f
Identify Chromium as Chrome 9 years ago
Lukas Reschke 015affb082
Missing returns + autoloader file 9 years ago
Roeland Jago Douma e351ba56f1
Move browserSupportsCspV3 to CSPNonceManager 9 years ago
Lukas Reschke 38b3ac8213
Add ContentSecurityPolicyNonceManager 9 years ago
Joas Schilling ba87db3fcc
Fix others 10 years ago
Lukas Reschke aba539703c
Update license headers 10 years ago
Roeland Jago Douma 9050e76d95
Move \OC\Security to PSR-4 10 years ago