Fix Content Security Policy
This commit is contained in:
parent
10ea494594
commit
c81271864d
@ -236,7 +236,7 @@ class Controller {
|
|||||||
$csp = [
|
$csp = [
|
||||||
"default-src 'self'",
|
"default-src 'self'",
|
||||||
"object-src 'none'",
|
"object-src 'none'",
|
||||||
'frame-src *.youtube.com',
|
"child-src 'self' *.youtube.com polyfill.io",
|
||||||
];
|
];
|
||||||
|
|
||||||
$view->addHeader('Content-Security-Policy', implode('; ', $csp));
|
$view->addHeader('Content-Security-Policy', implode('; ', $csp));
|
||||||
|
Loading…
Reference in New Issue
Block a user