4
Strict CSP doesn't work when rules are enforced by web server
Source: nextcloud/server#14980 · opened by @Dreamsorcerer
Strict CSP doesn't work when rules are enforced by web server: I was under the impression that Nextcloud was supporting strict CSPs now, but for Nextcloud (16.0.2) to run on my server, I still have to allow:
• ~~'unsafe-inline' in script-src~~ (PR #16380)
• 'unsafe-inline' in style-src
• data: in img-src
• data: in font-src
• ~~'unsafe-inline' in script-src~~ (PR #16380)
• 'unsafe-inline' in style-src
• data: in img-src
• data: in font-src
No pledges yet. Be the first to back this.
Comments
Similar requests
extend enforced sharing expiration date
1 vote · 0 comments
Obey enforced password setting for share by mail
1 vote · 0 comments
Possible to disable 2FA when 2FA is enforced
2 votes · 0 comments
Show full list of rules applied with password policy
5 votes · 0 comments
Support disabling automatic use of TLS
2 votes · 0 comments
No comments yet.