summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorlain <lain@soykaf.club>2020-04-15 12:05:22 +0200
committerrinpatch <rinpatch@sdf.org>2020-05-01 01:37:26 +0300
commita4afeed4266e75279422a6721f0a9a2aece0b9ea (patch)
tree0aef88400ed410a6598a505360f36f50094055bf
parent8cf4e1619e439b1c9374a52cfc2b0cdf8d549d02 (diff)
Uploads: Sandbox them in the CSP.
-rw-r--r--lib/pleroma/plugs/uploaded_media.ex1
1 files changed, 1 insertions, 0 deletions
diff --git a/lib/pleroma/plugs/uploaded_media.ex b/lib/pleroma/plugs/uploaded_media.ex
index 36ff024a7..94147e0c4 100644
--- a/lib/pleroma/plugs/uploaded_media.ex
+++ b/lib/pleroma/plugs/uploaded_media.ex
@@ -41,6 +41,7 @@ defmodule Pleroma.Plugs.UploadedMedia do
conn ->
conn
end
+ |> merge_resp_headers([{"content-security-policy", "sandbox"}])
config = Pleroma.Config.get(Pleroma.Upload)