Skip to content

Commit 3eaa80c

Browse files
authored
[5.x] Add CSP header to svg route (#14325)
1 parent b193c40 commit 3eaa80c

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

src/Http/Controllers/CP/Assets/SvgController.php

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,9 @@ public function show($asset)
2121

2222
$this->authorize('view', $asset);
2323

24-
return response($contents)->header('Content-Type', 'image/svg+xml');
24+
return response($contents)
25+
->header('Content-Type', 'image/svg+xml')
26+
->header('Content-Security-Policy', "script-src 'none'");
2527
}
2628

2729
/**

0 commit comments

Comments
 (0)