mirror of
https://github.com/swissmakers/swiss-datashare.git
synced 2026-04-05 07:47:01 +02:00
fix: use sandbox CSP for file previews
This commit is contained in:
@@ -78,7 +78,7 @@ export class FileController {
|
|||||||
"Content-Type":
|
"Content-Type":
|
||||||
mime?.lookup?.(file.metaData.name) || "application/octet-stream",
|
mime?.lookup?.(file.metaData.name) || "application/octet-stream",
|
||||||
"Content-Length": file.metaData.size,
|
"Content-Length": file.metaData.size,
|
||||||
"Content-Security-Policy": "script-src 'none'",
|
"Content-Security-Policy": "sandbox",
|
||||||
};
|
};
|
||||||
|
|
||||||
if (download === "true") {
|
if (download === "true") {
|
||||||
|
|||||||
Reference in New Issue
Block a user