mirror of
https://git.anonymousland.org/anonymousland/synapse.git
synced 2025-07-29 10:18:33 -04:00
Add Cross-Origin-Resource-Policy header to thumbnail and download media endpoints (#12944)
This commit is contained in:
parent
3c5549e74a
commit
9b683ea80f
5 changed files with 44 additions and 2 deletions
|
@ -15,7 +15,11 @@
|
|||
import logging
|
||||
from typing import TYPE_CHECKING
|
||||
|
||||
from synapse.http.server import DirectServeJsonResource, set_cors_headers
|
||||
from synapse.http.server import (
|
||||
DirectServeJsonResource,
|
||||
set_corp_headers,
|
||||
set_cors_headers,
|
||||
)
|
||||
from synapse.http.servlet import parse_boolean
|
||||
from synapse.http.site import SynapseRequest
|
||||
|
||||
|
@ -38,6 +42,7 @@ class DownloadResource(DirectServeJsonResource):
|
|||
|
||||
async def _async_render_GET(self, request: SynapseRequest) -> None:
|
||||
set_cors_headers(request)
|
||||
set_corp_headers(request)
|
||||
request.setHeader(
|
||||
b"Content-Security-Policy",
|
||||
b"sandbox;"
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue