mirror of
https://github.com/PrivateBin/PrivateBin.git
synced 2025-07-23 23:11:04 -04:00
introducing CSP header to mitigate XSS attacks, closes #10
This commit is contained in:
parent
a28aebae7d
commit
addb666a23
11 changed files with 75 additions and 18 deletions
|
@ -402,6 +402,7 @@ class PrivateBin
|
|||
header('Expires: ' . $time);
|
||||
header('Last-Modified: ' . $time);
|
||||
header('Vary: Accept');
|
||||
header('Content-Security-Policy: ' . $this->_conf->getKey('cspheader'));
|
||||
|
||||
// label all the expiration options
|
||||
$expire = array();
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue