Use CSP directive child-src in addition to frame-src
This commit is contained in:
parent
831552c396
commit
a23e0947e7
@ -41,6 +41,7 @@ Router\before(function ($action) {
|
|||||||
'media-src' => '*',
|
'media-src' => '*',
|
||||||
'img-src' => '* data:',
|
'img-src' => '* data:',
|
||||||
'frame-src' => Model\Config\get_iframe_whitelist(),
|
'frame-src' => Model\Config\get_iframe_whitelist(),
|
||||||
|
'child-src' => Model\Config\get_iframe_whitelist(),
|
||||||
'referrer' => 'no-referrer',
|
'referrer' => 'no-referrer',
|
||||||
));
|
));
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user