Uploads: Sandbox them in the CSP.
authorlain <lain@soykaf.club>
Wed, 15 Apr 2020 10:05:22 +0000 (12:05 +0200)
committerlain <lain@soykaf.club>
Wed, 15 Apr 2020 10:05:22 +0000 (12:05 +0200)
lib/pleroma/plugs/uploaded_media.ex

index 36ff024a7d6e562e2f90c0bf0025a373cd725e04..94147e0c42250c647984a3955dd98100208bc04f 100644 (file)
@@ -41,6 +41,7 @@ defmodule Pleroma.Plugs.UploadedMedia do
         conn ->
           conn
       end
+      |> merge_resp_headers([{"content-security-policy", "sandbox"}])
 
     config = Pleroma.Config.get(Pleroma.Upload)