X-Git-Url: http://git.shiar.nl/minimedit.git/blobdiff_plain/63c023f45bfa532dcc54b292906c150c10331e9e..992858b68f3a1feaae7940026676497f74cdbdcf:/page.php diff --git a/page.php b/page.php index 3dd8cba..93b705f 100644 --- a/page.php +++ b/page.php @@ -159,7 +159,12 @@ if ($PageAccess = $Article->restricted) { # prepare page contents -header("Content-Security-Policy: frame-ancestors 'none'"); +header(sprintf('Content-Security-Policy: %s', implode('; ', [ + "default-src 'self' 'unsafe-inline' http://cdn.ckeditor.com", # some overrides remain + "img-src 'self' data: http://cdn.ckeditor.com", # inline svg (in css) + "base-uri 'self'", # only local pages + "frame-ancestors 'none'", # prevent malicious embedding +]))); ob_start(); # page body $Place = [