Skip to content

Commit 4e5caf0

Browse files
author
Till Brehm
committed
Relax content security policy to allow images in webmail #6659
1 parent fa4d805 commit 4e5caf0

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

server/conf/apache_apps.vhost.master

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -38,8 +38,8 @@
3838

3939
<IfModule mod_headers.c>
4040
# ISPConfig 3.1 currently requires unsafe-line for both scripts and styles, as well as unsafe-eval
41-
Header set Content-Security-Policy "default-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src 'self' data:; object-src 'none'"
42-
<tmpl_var name="ssl_comment">Header set Content-Security-Policy "default-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src 'self' data:; object-src 'none'; upgrade-insecure-requests"
41+
Header set Content-Security-Policy "default-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src * data:; object-src 'none'"
42+
<tmpl_var name="ssl_comment">Header set Content-Security-Policy "default-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src 'self' data: *; object-src 'none'; upgrade-insecure-requests"
4343
Header set X-Content-Type-Options: nosniff
4444
Header set X-Frame-Options: SAMEORIGIN
4545
Header set X-XSS-Protection: "1; mode=block"

0 commit comments

Comments
 (0)