Changeset

13855:488483e1d915

Merge 13.0->trunk
author Matthew Wild <mwild1@gmail.com>
date Fri, 18 Apr 2025 12:25:38 +0100
parents 13853:5611ce3bc54c (current diff) 13854:0b01f40df0f9 (diff)
children 13856:14c1d6c7ac2d
files
diffstat 1 files changed, 1 insertions(+), 1 deletions(-) [+]
line wrap: on
line diff
--- a/plugins/mod_http_file_share.lua	Wed Apr 16 18:27:46 2025 +0200
+++ b/plugins/mod_http_file_share.lua	Fri Apr 18 12:25:38 2025 +0100
@@ -469,7 +469,7 @@
 	response.headers.accept_ranges = "bytes";
 
 	response.headers.cache_control = "max-age=31556952, immutable";
-	response.headers.content_security_policy =  "default-src 'none'; frame-ancestors 'none';"
+	response.headers.content_security_policy =  "default-src 'none'; media-src 'self'; frame-ancestors 'none';"
 	response.headers.strict_transport_security = "max-age=31556952";
 	response.headers.x_content_type_options = "nosniff";
 	response.headers.x_frame_options = "DENY"; -- COMPAT IE missing support for CSP frame-ancestors