X-Git-Url: http://git.shiar.nl/minimedit.git/blobdiff_plain/63c023f45bfa532dcc54b292906c150c10331e9e..bc04734cdf01d9b2ac8a9b9558c4782e61086821:/page.php diff --git a/page.php b/page.php index 3dd8cba..dee5ee0 100644 --- a/page.php +++ b/page.php @@ -159,7 +159,11 @@ if ($PageAccess = $Article->restricted) { # prepare page contents -header("Content-Security-Policy: frame-ancestors 'none'"); +header(sprintf('Content-Security-Policy: %s', implode('; ', [ + "default-src 'self' 'unsafe-inline' http://cdn.ckeditor.com", # some overrides remain + "img-src 'self' data: http://cdn.ckeditor.com", # inline svg (in css) + "frame-ancestors 'none'", # prevent malicious embedding +]))); ob_start(); # page body $Place = [