Merge pull request #17818 from vector-im/gsouquet/fix-6162

Enhance security by disallowing CSP object-src rule
This commit is contained in:
Germain 2021-06-29 15:33:32 +01:00 committed by GitHub
commit 4ba0e6bdee
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -35,7 +35,6 @@
worker-src 'self';
frame-src * blob: data:;
form-action 'self';
object-src 'self';
manifest-src 'self';
">
<% for (var i=0; i < htmlWebpackPlugin.files.css.length; i++) {