Merge pull request #20998 from owncloud/add-csp-header-to-static-resources

Add CSP header to static resources
This commit is contained in:
Thomas Müller 2015-12-07 16:23:38 +01:00
commit 3c0b584093

View file

@ -14,6 +14,10 @@
Header set X-Robots-Tag "none"
Header set X-Frame-Options "SAMEORIGIN"
SetEnv modHeadersAvailable true
# Add CSP header if not set, used for static resources
Header append Content-Security-Policy ""
Header edit Content-Security-Policy "^$" "default-src 'none'; style-src 'self' 'unsafe-inline'; script-src 'self'"
</IfModule>
# Add cache control for CSS and JS files