Page MenuHomePhabricator

D19154.diff
No OneTemporary

D19154.diff

diff --git a/src/aphront/response/AphrontResponse.php b/src/aphront/response/AphrontResponse.php
--- a/src/aphront/response/AphrontResponse.php
+++ b/src/aphront/response/AphrontResponse.php
@@ -144,6 +144,9 @@
$csp[] = "frame-ancestors 'none'";
}
+ // Block relics of the old world: Flash, Java applets, and so on.
+ $csp[] = "object-src 'none'";
+
$csp = implode('; ', $csp);
return $csp;

File Metadata

Mime Type
text/plain
Expires
Mon, Mar 31, 7:56 PM (2 w, 2 h ago)
Storage Engine
blob
Storage Format
Encrypted (AES-256-CBC)
Storage Handle
7384492
Default Alt Text
D19154.diff (424 B)

Event Timeline