Skip to content

Commit 254960e

Browse files
committed
Secure headers fix for elfinder and tinymce.
Signed-off-by: Joshua Parker <joshua@joshuaparker.dev>
1 parent f4a54b1 commit 254960e

File tree

1 file changed

+18
-2
lines changed

1 file changed

+18
-2
lines changed

config/headers.php

Lines changed: 18 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -416,16 +416,17 @@
416416

417417
'self' => true,
418418

419+
'data' => true,
420+
419421
'report-sample' => false,
420422

421423
'allow' => [
422424
'gravatar.com',
423425
'www.gravatar.com',
424-
'cdnjs.cloudflare.com/',
426+
'cdnjs.cloudflare.com',
425427
],
426428

427429
'schemes' => [
428-
'data:',
429430
'http:',
430431
'https:',
431432
],
@@ -518,6 +519,21 @@
518519
'unsafe-inline' => true,
519520
],
520521

522+
'frame-src' => [
523+
'none' => false,
524+
'self' => true,
525+
'allow' => [
526+
'cdnjs.cloudflare.com',
527+
],
528+
529+
'data' => true,
530+
531+
'schemes' => [
532+
'http:',
533+
'https:',
534+
],
535+
],
536+
521537
'style-src' => [
522538
'none' => false,
523539

0 commit comments

Comments
 (0)