Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

issue: iFrame Single Quotes #4844

Merged
merged 1 commit into from Apr 15, 2019

Conversation

Projects
None yet
2 participants
@JediKev
Copy link
Member

commented Apr 11, 2019

It's all about the single quotes baby! Apparently I can't read; the single quotes are only meant for word options such as 'self' and 'none'. When adding single quotes to the <host-source> options it takes them literally…too literally. For example, if your options are 'localhost:80 localhost:8080 localhost:8000' then 'localhost:80 and localhost:8000' will be seen as "invalid" due to the single quotes. This removes the single quotes from every line that sets the CSP so all options are valid. This also adds single quotes around the self option so it stays valid as well.

issue: iFrame Single Quotes
It's all about the single quotes baby! Apparently I can't read; the single
quotes are only meant for word options such as `'self'` and `'none'`. When
adding single quotes to the `<host-source>` options it takes them
literally…too literally. For example, if your options are `'localhost:80
localhost:8080 localhost:8000'` then `'localhost:80` and `localhost:8000'`
will be seen as "invalid" due to the single quotes. This removes the single
quotes from every line that sets the CSP so all options are valid. This also
adds single quotes around the `self` option so it stays valid as well.

@protich protich merged commit 020aa11 into osTicket:develop Apr 15, 2019

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.