Ferdinand Thiessen
|
a8f46af20f
chore: Add proper deprecation dates where missing
|
2 months ago |
provokateurin
|
9836e9b164
chore(deps): Update nextcloud/coding-standard to v1.3.1
|
2 months ago |
Daniel Kesselberg
|
af6de04e9e
style: update codestyle for coding-standard 1.2.3
|
3 months ago |
Ferdinand Thiessen
|
009761be58
test: Adjust tests for CSP nonce
|
4 months ago |
Ferdinand Thiessen
|
86f01a3358
fix: Make sure CSP nonce is not double base64 encoded
|
4 months ago |
Andy Scherzinger
|
dae7c159f7
chore: Add SPDX header
|
6 months ago |
Julius Härtl
|
78ba1b0712
fix: Allow nonce in csp header also if no other reasons are given
|
9 months ago |
Ferdinand Thiessen
|
ecf9f0a872
fix(CSP): Only add `strict-dynamic` when using nonces
|
1 year ago |
Ferdinand Thiessen
|
7df9eb3351
feat(ContentSecurityPolicy): Allow to set `strict-dynamic` on `script-src-elem` only
|
1 year ago |
Daniel Calviño Sánchez
|
41f2d912d2
Allow "wasm-unsafe-eval" in CSP
|
1 year ago |
Christoph Wurst
|
08a3f37695
chore(appframework)!: Drop \OCP\AppFramework\Http\EmptyContentSecurityPolicy::allowInlineScript
|
1 year ago |
Julius Härtl
|
bd03dd37be
Allow to set a strict-dynamic CSP through the API
|
2 years ago |
Carl Schwan
|
28970563a2
Remove some mentions of ownCloud from our api documentation
|
3 years ago |
John Molakvoæ (skjnldsv)
|
215aef3cbd
Update php licenses
|
3 years ago |
Roeland Jago Douma
|
9163790b7c
Set frame-ancestors to none if none are filled
|
4 years ago |
Julius Härtl
|
45a474071e
Remove @package annotations from public namespace
|
4 years ago |
Christoph Wurst
|
cb057829f7
Update license headers for 19
|
4 years ago |
Christoph Wurst
|
caff1023ea
Format control structures, classes, methods and function
|
4 years ago |
Christoph Wurst
|
1a9330cd69
Update the license headers for Nextcloud 19
|
4 years ago |
Pavel Krasikov
|
4c01326913
add docs for useJsNonce
|
4 years ago |
Christoph Wurst
|
5bf3d1bb38
Update license headers
|
5 years ago |
Roeland Jago Douma
|
35db32f504
Add deprecation warning
|
5 years ago |
Roeland Jago Douma
|
c4cafae884
frame-src doesn't respect the nonce attribute
|
5 years ago |
Roeland Jago Douma
|
f94ee72507
Add form-action CSP element
|
5 years ago |
Roeland Jago Douma
|
4d8e1f6c67
CSP: set nonce for iframes
|
5 years ago |
Roeland Jago Douma
|
579822b6a5
Add report-uri to CSP
|
6 years ago |
Roeland Jago Douma
|
8354c50911
Deprecate the childSrc functions
|
6 years ago |
Roeland Jago Douma
|
c8fe4b4fc8
Add workerSrc to CSP
|
6 years ago |
Morris Jobke
|
0eebff152a
Update license headers
|
7 years ago |
Thomas Citharel
|
eb51c46549
fix typo and set @since properly
|
7 years ago |