ui-blob: set CSP just in case

This commit is contained in:
Jason A. Donenfeld 2016-01-14 14:43:43 +01:00
parent 92996ac2a6
commit 9ca2566972
1 changed files with 3 additions and 0 deletions

View File

@ -166,6 +166,9 @@ void cgit_print_blob(const char *hex, char *path, const char *head, int file_onl
else
ctx.page.mimetype = "text/plain";
ctx.page.filename = path;
html("X-Content-Type-Options: nosniff\n");
html("Content-Security-Policy: default-src 'none'\n");
cgit_print_http_headers();
html_raw(buf, size);
free(buf);