#4559 Fix and improve the default CSP_HEADERS
Merged by pingou. Opened by pingou.
more_csp_changes  into  master

Download 4559.patch

Signed-off-by: Pierre-Yves Chibon pingou@pingoured.fr

rebased onto c163154682991138a115879369da29d5b489f139

:thumbsup:

Does docs work with this? We don't have a frame-src and default does not include https: after this. Embedded docs iframe should fail.

We could add frame-src and connect-src statements when docs and ev are enabled on the config

This is the default and should be tweaked by the admins according to their configuration. Since we do not have neither EV nor docs on by default I think it's fine as is.

However, it may be good to make this explicit in the docs, would you like to open a PR to that end?

works for me. :thumbsup:

Thanks :)

Pull-Request has been merged by pingou

Metadata