Merge pull request #1222 from hedgedoc/fix/upgrade_insecure_requests
Fix upgradeInsecureRequests CSP directive
This commit is contained in:
commit
140b2c261c
@ -85,9 +85,9 @@ function getCspNonce (req, res) {
|
|||||||
|
|
||||||
function addUpgradeUnsafeRequestsOptionTo (directives) {
|
function addUpgradeUnsafeRequestsOptionTo (directives) {
|
||||||
if (config.csp.upgradeInsecureRequests === 'auto' && config.useSSL) {
|
if (config.csp.upgradeInsecureRequests === 'auto' && config.useSSL) {
|
||||||
directives.upgradeInsecureRequests = true
|
directives.upgradeInsecureRequests = []
|
||||||
} else if (config.csp.upgradeInsecureRequests === true) {
|
} else if (config.csp.upgradeInsecureRequests === true) {
|
||||||
directives.upgradeInsecureRequests = true
|
directives.upgradeInsecureRequests = []
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user