Skip to content

Commit e63889a

Browse files
author
Till Brehm
committed
Merge branch '6659-probable-bug-on-roundcube-default-content-security-policy' into 'develop'
Resolve "Probable bug on roundcube default Content-Security-Policy" Closes #6659 See merge request ispconfig/ispconfig3!1901
2 parents f042d94 + 4e5caf0 commit e63889a

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

server/conf/apache_apps.vhost.master

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -38,8 +38,8 @@
3838

3939
<IfModule mod_headers.c>
4040
# ISPConfig 3.1 currently requires unsafe-line for both scripts and styles, as well as unsafe-eval
41-
Header set Content-Security-Policy "default-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src 'self' data:; object-src 'none'"
42-
<tmpl_var name="ssl_comment">Header set Content-Security-Policy "default-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src 'self' data:; object-src 'none'; upgrade-insecure-requests"
41+
Header set Content-Security-Policy "default-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src * data:; object-src 'none'"
42+
<tmpl_var name="ssl_comment">Header set Content-Security-Policy "default-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src 'self' data: *; object-src 'none'; upgrade-insecure-requests"
4343
Header set X-Content-Type-Options: nosniff
4444
Header set X-Frame-Options: SAMEORIGIN
4545
Header set X-XSS-Protection: "1; mode=block"

0 commit comments

Comments
 (0)