From 93e69ab0c69fc9d3eca6dc992505984cfb911390 Mon Sep 17 00:00:00 2001 From: snipe Date: Fri, 1 Mar 2024 11:44:49 +0000 Subject: [PATCH] Removed unsafe-inline and unsafe-eval Signed-off-by: snipe --- app/Http/Middleware/SecurityHeaders.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/app/Http/Middleware/SecurityHeaders.php b/app/Http/Middleware/SecurityHeaders.php index 25f0461fc..af13156da 100644 --- a/app/Http/Middleware/SecurityHeaders.php +++ b/app/Http/Middleware/SecurityHeaders.php @@ -83,8 +83,8 @@ class SecurityHeaders if ((config('app.debug') != 'true') && (config('app.enable_csp') == 'true')) { $csp_policy[] = "default-src 'self'"; - $csp_policy[] = "style-src 'self' 'unsafe-inline'"; - $csp_policy[] = "script-src 'self' 'unsafe-inline' 'unsafe-eval'"; + $csp_policy[] = "style-src 'self'"; + $csp_policy[] = "script-src 'self'"; $csp_policy[] = "connect-src 'self'"; $csp_policy[] = "object-src 'none'"; $csp_policy[] = "font-src 'self' data:";