|
88 | 88 |
|
89 | 89 | <title>{{ settings.hostname }} :: Pimcore</title> |
90 | 90 |
|
91 | | - <script> |
| 91 | + <script {{ pimcore_csp.getNonceHtmlAttribute()|raw }}> |
92 | 92 | var pimcore = {}; // namespace |
93 | 93 |
|
94 | 94 | // hide symfony toolbar by default |
|
98 | 98 | } |
99 | 99 | </script> |
100 | 100 |
|
101 | | - <script src="{{ asset('bundles/fosjsrouting/js/router.js') }}"></script> |
102 | | - <script src="{{ path('fos_js_routing_js', {'callback' : 'fos.Router.setData'}) }}"></script> |
| 101 | + <script src="{{ asset('bundles/fosjsrouting/js/router.js') }}" {{ pimcore_csp.getNonceHtmlAttribute()|raw }}></script> |
| 102 | + <script src="{{ path('fos_js_routing_js', {'callback' : 'fos.Router.setData'}) }}" {{ pimcore_csp.getNonceHtmlAttribute()|raw }}></script> |
103 | 103 | </head> |
104 | 104 |
|
105 | 105 | <body class="pimcore_version_10" data-app-env="{{ app.environment }}"> |
|
698 | 698 |
|
699 | 699 | <!-- some javascript --> |
700 | 700 | {# pimcore constants #} |
701 | | -<script> |
| 701 | +<script {{ pimcore_csp.getNonceHtmlAttribute()|raw }}> |
702 | 702 | pimcore.settings = {{(settings|json_encode(constant('JSON_PRETTY_PRINT'))|raw)}}; |
703 | 703 | </script> |
704 | 704 |
|
705 | | -<script src="{{ path('pimcore_admin_misc_jsontranslationssystem', {'language': language, '_dc': settings.build }) }}"></script> |
706 | | -<script src="{{ path('pimcore_admin_user_getcurrentuser', {'_dc': settings.build }) }}"></script> |
707 | | -<script src="{{ path('pimcore_admin_misc_availablelanguages', {'_dc': settings.build }) }}"></script> |
| 705 | +<script src="{{ path('pimcore_admin_misc_jsontranslationssystem', {'language': language, '_dc': settings.build }) }}" {{ pimcore_csp.getNonceHtmlAttribute()|raw }}></script> |
| 706 | +<script src="{{ path('pimcore_admin_user_getcurrentuser', {'_dc': settings.build }) }}" {{ pimcore_csp.getNonceHtmlAttribute()|raw }}></script> |
| 707 | +<script src="{{ path('pimcore_admin_misc_availablelanguages', {'_dc': settings.build }) }}" {{ pimcore_csp.getNonceHtmlAttribute()|raw }}></script> |
708 | 708 |
|
709 | 709 | <!-- library scripts --> |
710 | 710 | {% for scriptUrl in scriptLibs %} |
711 | | - <script src="/bundles/pimcoreadmin/js/{{ scriptUrl }}?_dc={{ settings.build }}"></script> |
| 711 | + <script src="/bundles/pimcoreadmin/js/{{ scriptUrl }}?_dc={{ settings.build }}" {{ pimcore_csp.getNonceHtmlAttribute()|raw }}></script> |
712 | 712 | {% endfor %} |
713 | 713 |
|
714 | 714 | <!-- internal scripts --> |
|
734 | 734 | <!-- bundle scripts --> |
735 | 735 | {% if settings.disableMinifyJs %} |
736 | 736 | {% for pluginJsPath in pluginJsPaths %} |
737 | | - <script src="{{ pluginJsPath }}?_dc={{ pluginDcValue }}"></script> |
| 737 | + <script src="{{ pluginJsPath }}?_dc={{ pluginDcValue }}" {{ pimcore_csp.getNonceHtmlAttribute()|raw }}></script> |
738 | 738 | {% endfor %} |
739 | 739 | {% else %} |
740 | 740 | {{ pimcore_minimize_scripts(pluginJsPaths)|raw }} |
|
745 | 745 | {% endfor %} |
746 | 746 |
|
747 | 747 | {# MUST BE THE LAST LINE #} |
748 | | -<script src="/bundles/pimcoreadmin/js/pimcore/startup.js?_dc={{ settings.build }}"></script> |
| 748 | +<script src="/bundles/pimcoreadmin/js/pimcore/startup.js?_dc={{ settings.build }}" {{ pimcore_csp.getNonceHtmlAttribute()|raw }}></script> |
749 | 749 | </body> |
750 | 750 | </html> |
0 commit comments