Ferdinand Thiessen
|
ecf9f0a872
fix(CSP): Only add `strict-dynamic` when using nonces
|
hai 1 ano |
Ferdinand Thiessen
|
e231abd9bf
fix!(ContentSecurityPolicy): Make `strict-dynamic` enabled by default on `script-src-elem`
|
hai 1 ano |
Ferdinand Thiessen
|
7df9eb3351
feat(ContentSecurityPolicy): Allow to set `strict-dynamic` on `script-src-elem` only
|
hai 1 ano |
Daniel Calviño Sánchez
|
41f2d912d2
Allow "wasm-unsafe-eval" in CSP
|
hai 1 ano |
Christoph Wurst
|
08a3f37695
chore(appframework)!: Drop \OCP\AppFramework\Http\EmptyContentSecurityPolicy::allowInlineScript
|
hai 1 ano |
Côme Chilliet
|
f5c361cf44
composer run cs:fix
|
hai 1 ano |
Julius Härtl
|
bd03dd37be
Allow to set a strict-dynamic CSP through the API
|
%!s(int64=2) %!d(string=hai) anos |
Christoph Wurst
|
74936c49ea
Remove unused imports
|
%!s(int64=4) %!d(string=hai) anos |
Roeland Jago Douma
|
3a7cf40aaa
Mode to modern phpunit
|
%!s(int64=5) %!d(string=hai) anos |
Roeland Jago Douma
|
c007ca624f
Make phpunit8 compatible
|
%!s(int64=5) %!d(string=hai) anos |
Roeland Jago Douma
|
68748d4f85
Some php-cs fixes
|
%!s(int64=5) %!d(string=hai) anos |
Roeland Jago Douma
|
cf647451e5
Update CSP test cases to handle the new form-action
|
%!s(int64=5) %!d(string=hai) anos |
Roeland Jago Douma
|
ad676c0102
Set default frame-ancestors to 'self'
|
%!s(int64=5) %!d(string=hai) anos |
Roeland Jago Douma
|
64244e1a4f
CSP: Allow fonts to be provided in data
|
%!s(int64=5) %!d(string=hai) anos |
Roeland Jago Douma
|
5b61ef9213
Disallow unsafe-eval by default
|
%!s(int64=6) %!d(string=hai) anos |
Thomas Citharel
|
ecf347bd1a
Add CSP frame-ancestors support
|
%!s(int64=7) %!d(string=hai) anos |
Morris Jobke
|
f9bc53146d
Fix unit tests
|
%!s(int64=7) %!d(string=hai) anos |
Lukas Reschke
|
adfd1e63f6
Add base-uri to CSP policy
|
%!s(int64=7) %!d(string=hai) anos |
Joas Schilling
|
94ad54ec9b
Move tests/ to PSR-4 (#24731)
|
%!s(int64=8) %!d(string=hai) anos |