We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent b193c40 commit 3eaa80cCopy full SHA for 3eaa80c
1 file changed
src/Http/Controllers/CP/Assets/SvgController.php
@@ -21,7 +21,9 @@ public function show($asset)
21
22
$this->authorize('view', $asset);
23
24
- return response($contents)->header('Content-Type', 'image/svg+xml');
+ return response($contents)
25
+ ->header('Content-Type', 'image/svg+xml')
26
+ ->header('Content-Security-Policy', "script-src 'none'");
27
}
28
29
/**
0 commit comments