X-Git-Url: http://git.shiar.nl/minimedit.git/blobdiff_plain/bc04734cdf01d9b2ac8a9b9558c4782e61086821..a034b7a3f5b363f74a47c9f20bfa0cf4f2988b34:/page.php diff --git a/page.php b/page.php index dee5ee0..93b705f 100644 --- a/page.php +++ b/page.php @@ -162,6 +162,7 @@ if ($PageAccess = $Article->restricted) { header(sprintf('Content-Security-Policy: %s', implode('; ', [ "default-src 'self' 'unsafe-inline' http://cdn.ckeditor.com", # some overrides remain "img-src 'self' data: http://cdn.ckeditor.com", # inline svg (in css) + "base-uri 'self'", # only local pages "frame-ancestors 'none'", # prevent malicious embedding ])));