forked from I2P_Developers/i2p.i2p
Fix CSP to allow inline style and refresh
Add filter to all webapps
This commit is contained in:
@ -32,7 +32,7 @@
|
||||
// clickjacking
|
||||
if (intl.shouldSendXFrame()) {
|
||||
response.setHeader("X-Frame-Options", "SAMEORIGIN");
|
||||
response.setHeader("Content-Security-Policy", "default-src 'self'");
|
||||
response.setHeader("Content-Security-Policy", "default-src 'self'; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline'");
|
||||
response.setHeader("X-XSS-Protection", "1; mode=block");
|
||||
}
|
||||
|
||||
|
Reference in New Issue
Block a user