ui-blob: set CSP just in case
This commit is contained in:
parent
92996ac2a6
commit
9ca2566972
@ -166,6 +166,9 @@ void cgit_print_blob(const char *hex, char *path, const char *head, int file_onl
|
|||||||
else
|
else
|
||||||
ctx.page.mimetype = "text/plain";
|
ctx.page.mimetype = "text/plain";
|
||||||
ctx.page.filename = path;
|
ctx.page.filename = path;
|
||||||
|
|
||||||
|
html("X-Content-Type-Options: nosniff\n");
|
||||||
|
html("Content-Security-Policy: default-src 'none'\n");
|
||||||
cgit_print_http_headers();
|
cgit_print_http_headers();
|
||||||
html_raw(buf, size);
|
html_raw(buf, size);
|
||||||
free(buf);
|
free(buf);
|
||||||
|
Loading…
Reference in New Issue
Block a user