X-Git-Url: http://git.shiar.net/minimedit.git/blobdiff_plain/1b6e24cdaae9bf6bf6a990fe9227cb50f5d29d92..f2df190a6c4a0128eb351bc398cffd0edf8d6096:/page.php?ds=sidebyside diff --git a/page.php b/page.php index 12e0690..93b705f 100644 --- a/page.php +++ b/page.php @@ -159,6 +159,13 @@ if ($PageAccess = $Article->restricted) { # prepare page contents +header(sprintf('Content-Security-Policy: %s', implode('; ', [ + "default-src 'self' 'unsafe-inline' http://cdn.ckeditor.com", # some overrides remain + "img-src 'self' data: http://cdn.ckeditor.com", # inline svg (in css) + "base-uri 'self'", # only local pages + "frame-ancestors 'none'", # prevent malicious embedding +]))); + ob_start(); # page body $Place = [ 'user' => $User ? $User->login : '',