Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Restrict content security policy to load data only from current origin
Remove frame-acestors completely because it isn't included into an iframe anymore. If this is still required the CSP settings can be adjusted via a command line parameter. More important don't allow executing javascript from inline html. Only from references javascript files. But allow to load CSS from inline <style> elements via style-src-elem (not supported by firefox yet) and style-src CSP settings. Fixes AP-1507
- Loading branch information