Skip to content

Commit df7ed74

Browse files
committed
fix: remove legacy CSP eval allowance
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
1 parent 74e07ba commit df7ed74

2 files changed

Lines changed: 0 additions & 3 deletions

File tree

lib/Controller/PageController.php

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -120,7 +120,6 @@ public function index(): TemplateResponse {
120120
$response = new TemplateResponse(Application::APP_ID, 'main');
121121

122122
$policy = new ContentSecurityPolicy();
123-
$policy->allowEvalScript(true);
124123
$policy->addAllowedFrameDomain('\'self\'');
125124
$policy->addAllowedWorkerSrcDomain("'self'");
126125
$response->setContentSecurityPolicy($policy);
@@ -387,7 +386,6 @@ public function sign(string $uuid): TemplateResponse {
387386
$response = new TemplateResponse(Application::APP_ID, 'external', [], TemplateResponse::RENDER_AS_BASE);
388387

389388
$policy = new ContentSecurityPolicy();
390-
$policy->allowEvalScript(true);
391389
$policy->addAllowedWorkerSrcDomain("'self'");
392390
$response->setContentSecurityPolicy($policy);
393391

lib/Middleware/InjectionMiddleware.php

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -326,7 +326,6 @@ public function afterException($controller, $methodName, \Exception $exception):
326326
);
327327

328328
$policy = new ContentSecurityPolicy();
329-
$policy->allowEvalScript(true);
330329
$policy->addAllowedFrameDomain('\'self\'');
331330
$response->setContentSecurityPolicy($policy);
332331
return $response;

0 commit comments

Comments
 (0)