1
0
mirror of https://github.com/imgproxy/imgproxy.git synced 2025-01-08 10:45:04 +02:00

Set Content-Security-Policy tag when the raw option is used

This commit is contained in:
DarthSim 2023-02-25 18:58:44 +03:00
parent 62f8d08a93
commit 70d657113e

View File

@ -118,6 +118,7 @@ func streamOriginImage(ctx context.Context, reqID string, r *http.Request, rw ht
"Expires": rw.Header().Get("Expires"),
})
setCanonical(rw, imageURL)
rw.Header().Set("Content-Security-Policy", "script-src 'none'")
rw.WriteHeader(res.StatusCode)