Browse Source

Merge branch 'CSP-no-inline' into dev

Alexandre Alapetite 10 years ago
parent
commit
e0fe98d74f
1 changed files with 1 additions and 1 deletions
  1. 1 1
      app/FreshRSS.php

+ 1 - 1
app/FreshRSS.php

@@ -168,7 +168,7 @@ class FreshRSS extends Minz_FrontController {
 	}
 
 	public static function preLayout() {
-		header("Content-Security-Policy: default-src 'self'; img-src * data:; media-src *; style-src 'self' 'unsafe-inline'");
+		header("Content-Security-Policy: default-src 'self'; child-src *; img-src * data:; media-src *; style-src 'self' 'unsafe-inline'");
 		self::setJavascriptCookie();
 	}