Merge pull request #1600 from turt2live/travis/c2s/media-csp

Specify the minimum CSP for media
pull/1573/head
Travis Ralston 6 years ago committed by GitHub
commit c127eed7e7
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

@ -0,0 +1 @@
Recommend that servers set a Content Security Policy for the content repository.

@ -33,6 +33,10 @@ recipient's local homeserver, which must first transfer the content from the
origin homeserver using the same API (unless the origin and destination
homeservers are the same).
When serving content, the server SHOULD provide a ``Content-Security-Policy``
header. The recommended policy is ``default-src 'none'; script-src 'none';
plugin-types application/pdf; style-src 'unsafe-inline'; object-src 'self';``.
Client behaviour
----------------

Loading…
Cancel
Save