Move CSP to config

This commit is contained in:
Max Berger
2026-03-20 08:21:40 +01:00
parent fdd7f784d0
commit 5b43c9e5bd
3 changed files with 5 additions and 1 deletions

3
config
View File

@@ -431,6 +431,9 @@
# Additional HTTP headers
#Access-Control-Allow-Origin = *
# Set CSP to disallow execution of unknown javascript
# This may become the default in future versions, override if you need a different CSP.
Content-Security-Policy = default-src 'self'; object-src 'none'
[hook]

View File

@@ -53,6 +53,8 @@ type = htpasswd
htpasswd_filename = {user_path}
[web]
type = internal
[headers]
Content-Security-Policy = default-src 'self'; object-src 'none'
[sharing]
type = csv
collection_by_map = true

View File

@@ -200,7 +200,6 @@ def _serve_traversable(
os.path.splitext(traversable.name)[1].lower(), FALLBACK_MIMETYPE)
headers = {
"Content-Type": content_type,
"Content-Security-Policy": "default-src 'self'; object-src 'none'"
}
if isinstance(traversable, pathlib.Path):
headers["Last-Modified"] = time.strftime(