diff --git a/CHANGELOG.md b/CHANGELOG.md index 9de58012..4b21942a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,12 +3,19 @@ ## 3.7.0.dev * Feature: collection sharing by map or token incl. management API and WebUI extension +* Feature: share address book collection as birthday calendar * Add: [auth] oauth2: allow custom client_id and client_secret (optional) * Cleanup: deprecate config option 'ldap_use_ssl' for good +* Cleanup: WebUI is now split into smaller javascript files +* Cleanup: WebUI is now fit for strict content security policy +* Cleanup: WebUI: Simplfied Caching and Navigation internally +* Cleanup: WebUI: Unified error handling +* Cleanup: Added integration test for verification of end-to-end behavior of WebUI * Performance: improve `path_to_filesystem()` * Performance: preload access rights from file * Add: [server] delay_on_error option * Add: [logging] limit_content option +* Add: [headers] Content-Security-Policy is now set to be strict on new configs ## 3.6.1 diff --git a/config b/config index 98e13af2..b2bddd5b 100644 --- a/config +++ b/config @@ -431,6 +431,9 @@ # Additional HTTP headers #Access-Control-Allow-Origin = * +# Set CSP to disallow execution of unknown javascript +# This may become the default in future versions, override if you need a different CSP. +Content-Security-Policy = default-src 'self'; object-src 'none' [hook] diff --git a/integ_tests/common.py b/integ_tests/common.py index ca1527f3..06a6a4a3 100644 --- a/integ_tests/common.py +++ b/integ_tests/common.py @@ -53,6 +53,8 @@ type = htpasswd htpasswd_filename = {user_path} [web] type = internal +[headers] +Content-Security-Policy = default-src 'self'; object-src 'none' [sharing] type = csv collection_by_map = true diff --git a/radicale/httputils.py b/radicale/httputils.py index ddad1eac..424f178e 100644 --- a/radicale/httputils.py +++ b/radicale/httputils.py @@ -200,7 +200,6 @@ def _serve_traversable( os.path.splitext(traversable.name)[1].lower(), FALLBACK_MIMETYPE) headers = { "Content-Type": content_type, - "Content-Security-Policy": "default-src 'self'; object-src 'none'" } if isinstance(traversable, pathlib.Path): headers["Last-Modified"] = time.strftime(