Tightened up the content security policy for non HTML files.

This commit is contained in:
CalDescent 2022-03-01 20:36:34 +00:00
parent e392e4d344
commit 69309c437e

View File

@ -128,7 +128,7 @@ public class ArbitraryDataRenderer {
// Regular file - can be streamed directly // Regular file - can be streamed directly
File file = new File(filePath); File file = new File(filePath);
FileInputStream inputStream = new FileInputStream(file); FileInputStream inputStream = new FileInputStream(file);
response.addHeader("Content-Security-Policy", "default-src 'self' 'unsafe-inline'; media-src 'self' blob:"); response.addHeader("Content-Security-Policy", "default-src 'self'");
response.setContentType(context.getMimeType(filename)); response.setContentType(context.getMimeType(filename));
int bytesRead, length = 0; int bytesRead, length = 0;
byte[] buffer = new byte[10240]; byte[] buffer = new byte[10240];