commit eda46314405cb94c451d20b781435f8652bb0a1e
parent 0a12b5e4b0316018967c01525ebf46583229ce2e
Author: Jan Dankert <devnull@localhost>
Date: Tue, 10 Jul 2018 23:28:08 +0200
CSP child-src ist deprecated, daher ersetzt.
Diffstat:
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/modules/cms-ui/UI.class.php b/modules/cms-ui/UI.class.php
@@ -195,7 +195,8 @@ class UI
'img-src \'self\'',
// No <audio>, <video> elements
'media-src \'none\'',
- 'child-src \'self\'',
+ 'frame-src \'self\'',
+ 'worker-src \'self\'',
'form-action \'self\'',
'font-src \'none\'',
// Ajax-Calls