mirror of https://github.com/gogs/gogs.git
attachment: set CSP header in the serving endpoint (#6926)
parent
a61a4389ec
commit
cb35b73048
|
@ -318,6 +318,7 @@ func runWeb(c *cli.Context) error {
|
||||||
}
|
}
|
||||||
defer fr.Close()
|
defer fr.Close()
|
||||||
|
|
||||||
|
c.Header().Set("Content-Security-Policy", "default-src 'none'; style-src 'unsafe-inline'; sandbox")
|
||||||
c.Header().Set("Cache-Control", "public,max-age=86400")
|
c.Header().Set("Cache-Control", "public,max-age=86400")
|
||||||
c.Header().Set("Content-Disposition", fmt.Sprintf(`inline; filename="%s"`, attach.Name))
|
c.Header().Set("Content-Disposition", fmt.Sprintf(`inline; filename="%s"`, attach.Name))
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue