mirror of
https://github.com/hedgedoc/hedgedoc.git
synced 2024-11-25 03:06:31 -05:00
Merge pull request #1222 from hedgedoc/fix/upgrade_insecure_requests
Fix upgradeInsecureRequests CSP directive
This commit is contained in:
commit
140b2c261c
1 changed files with 2 additions and 2 deletions
|
@ -85,9 +85,9 @@ function getCspNonce (req, res) {
|
||||||
|
|
||||||
function addUpgradeUnsafeRequestsOptionTo (directives) {
|
function addUpgradeUnsafeRequestsOptionTo (directives) {
|
||||||
if (config.csp.upgradeInsecureRequests === 'auto' && config.useSSL) {
|
if (config.csp.upgradeInsecureRequests === 'auto' && config.useSSL) {
|
||||||
directives.upgradeInsecureRequests = true
|
directives.upgradeInsecureRequests = []
|
||||||
} else if (config.csp.upgradeInsecureRequests === true) {
|
} else if (config.csp.upgradeInsecureRequests === true) {
|
||||||
directives.upgradeInsecureRequests = true
|
directives.upgradeInsecureRequests = []
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
Loading…
Reference in a new issue