X-Git-Url: http://git.shiar.net/minimedit.git/blobdiff_plain/bc04734cdf01d9b2ac8a9b9558c4782e61086821..992858b68f3a1feaae7940026676497f74cdbdcf:/page.php?ds=sidebyside diff --git a/page.php b/page.php index dee5ee0..93b705f 100644 --- a/page.php +++ b/page.php @@ -162,6 +162,7 @@ if ($PageAccess = $Article->restricted) { header(sprintf('Content-Security-Policy: %s', implode('; ', [ "default-src 'self' 'unsafe-inline' http://cdn.ckeditor.com", # some overrides remain "img-src 'self' data: http://cdn.ckeditor.com", # inline svg (in css) + "base-uri 'self'", # only local pages "frame-ancestors 'none'", # prevent malicious embedding ])));