mirror of
https://github.com/humhub/humhub.git
synced 2025-01-16 21:58:17 +01:00
Fix #3945: Default object-src policy prevents loading pdf on safari
This commit is contained in:
parent
a6474bab8f
commit
731e105449
@ -49,7 +49,7 @@ $config = [
|
||||
"Referrer-Policy" => "no-referrer-when-downgrade",
|
||||
"X-Permitted-Cross-Domain-Policies" => "master-only",
|
||||
"X-Frame-Options" => "sameorigin",
|
||||
"Content-Security-Policy" => "default-src *; connect-src *; font-src 'self'; frame-src https://* http://* *; img-src https://* http://* * data:; object-src 'none'; script-src 'self' https://* http://* * 'unsafe-inline' 'report-sample'; style-src * https://* http://* * 'unsafe-inline';"
|
||||
"Content-Security-Policy" => "default-src *; connect-src *; font-src 'self'; frame-src https://* http://* *; img-src https://* http://* * data:; object-src 'self'; script-src 'self' https://* http://* * 'unsafe-inline' 'report-sample'; style-src * https://* http://* * 'unsafe-inline';"
|
||||
]
|
||||
]
|
||||
]
|
||||
|
@ -1,6 +1,10 @@
|
||||
HumHub Change Log
|
||||
=================
|
||||
|
||||
1.4.5 (Unreleased)
|
||||
----------------------
|
||||
- Fix #3945: Default object-src policy prevents loading pdf on safari
|
||||
|
||||
1.4.4 (March 24, 2020)
|
||||
----------------------
|
||||
- Fix #3908: `DateHelper::parseDateTime()` returns invalid date if given value is not parsable
|
||||
|
@ -57,6 +57,7 @@ return [
|
||||
"unsafe-inline" => true
|
||||
],
|
||||
"object-src" => [
|
||||
'self' => true
|
||||
],
|
||||
"frame-src" => [
|
||||
"allow" => [
|
||||
|
Loading…
x
Reference in New Issue
Block a user