mirror of
https://github.com/nextcloud/server.git
synced 2025-01-30 22:37:01 +00:00
2916e5df7e
This way we use the CSP nonce for dynamically loaded scripts. Important to notice: The CSP nonce must NOT be injected in `content` as this can lead to value exfiltration using e.g. side-channel attacts (CSS selectors). Signed-off-by: Ferdinand Thiessen <opensource@fthiessen.de> |
||
---|---|---|
.. | ||
Base.php | ||
CSSResourceLocator.php | ||
JSCombiner.php | ||
JSConfigHelper.php | ||
JSResourceLocator.php | ||
ResourceLocator.php | ||
ResourceNotFoundException.php | ||
TemplateFileLocator.php |