Skip to content
Snippets Groups Projects
Commit 0af9e1a6 authored by Erik Johnston's avatar Erik Johnston
Browse files

Set `Content-Security-Policy` on media repo

This is to inform browsers that they should sandbox the returned
media. This is particularly cruical for javascript/HTML files.
parent f90b3d83
No related branches found
No related tags found
No related merge requests found
......@@ -45,6 +45,7 @@ class DownloadResource(Resource):
@request_handler()
@defer.inlineCallbacks
def _async_render_GET(self, request):
request.setHeader("Content-Security-Policy", "sandbox")
server_name, media_id, name = parse_media_id(request)
if server_name == self.server_name:
yield self._respond_local_file(request, media_id, name)
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment