File tree Expand file tree Collapse file tree 1 file changed +2
-2
lines changed
Expand file tree Collapse file tree 1 file changed +2
-2
lines changed Original file line number Diff line number Diff line change 3838
3939 <IfModule mod_headers.c>
4040 # ISPConfig 3.1 currently requires unsafe-line for both scripts and styles, as well as unsafe-eval
41- Header set Content-Security-Policy "default-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src 'self' data:; object-src 'none'"
42- <tmpl_var name="ssl_comment">Header set Content-Security-Policy "default-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src 'self' data:; object-src 'none'; upgrade-insecure-requests"
41+ Header set Content-Security-Policy "default-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src * data:; object-src 'none'"
42+ <tmpl_var name="ssl_comment">Header set Content-Security-Policy "default-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src 'self' data: * ; object-src 'none'; upgrade-insecure-requests"
4343 Header set X-Content-Type-Options: nosniff
4444 Header set X-Frame-Options: SAMEORIGIN
4545 Header set X-XSS-Protection: "1; mode=block"
You can’t perform that action at this time.
0 commit comments