Move CSP to config
This commit is contained in:
3
config
3
config
@@ -431,6 +431,9 @@
|
|||||||
# Additional HTTP headers
|
# Additional HTTP headers
|
||||||
#Access-Control-Allow-Origin = *
|
#Access-Control-Allow-Origin = *
|
||||||
|
|
||||||
|
# Set CSP to disallow execution of unknown javascript
|
||||||
|
# This may become the default in future versions, override if you need a different CSP.
|
||||||
|
Content-Security-Policy = default-src 'self'; object-src 'none'
|
||||||
|
|
||||||
[hook]
|
[hook]
|
||||||
|
|
||||||
|
|||||||
@@ -53,6 +53,8 @@ type = htpasswd
|
|||||||
htpasswd_filename = {user_path}
|
htpasswd_filename = {user_path}
|
||||||
[web]
|
[web]
|
||||||
type = internal
|
type = internal
|
||||||
|
[headers]
|
||||||
|
Content-Security-Policy = default-src 'self'; object-src 'none'
|
||||||
[sharing]
|
[sharing]
|
||||||
type = csv
|
type = csv
|
||||||
collection_by_map = true
|
collection_by_map = true
|
||||||
|
|||||||
@@ -200,7 +200,6 @@ def _serve_traversable(
|
|||||||
os.path.splitext(traversable.name)[1].lower(), FALLBACK_MIMETYPE)
|
os.path.splitext(traversable.name)[1].lower(), FALLBACK_MIMETYPE)
|
||||||
headers = {
|
headers = {
|
||||||
"Content-Type": content_type,
|
"Content-Type": content_type,
|
||||||
"Content-Security-Policy": "default-src 'self'; object-src 'none'"
|
|
||||||
}
|
}
|
||||||
if isinstance(traversable, pathlib.Path):
|
if isinstance(traversable, pathlib.Path):
|
||||||
headers["Last-Modified"] = time.strftime(
|
headers["Last-Modified"] = time.strftime(
|
||||||
|
|||||||
Reference in New Issue
Block a user