Merge pull request #1222 from hedgedoc/fix/upgrade_insecure_requests

Fix upgradeInsecureRequests CSP directive
This commit is contained in:
David Mehren
2021-05-06 21:18:46 +02:00
committed by GitHub

View File

@@ -85,9 +85,9 @@ function getCspNonce (req, res) {
function addUpgradeUnsafeRequestsOptionTo (directives) {
if (config.csp.upgradeInsecureRequests === 'auto' && config.useSSL) {
directives.upgradeInsecureRequests = true
directives.upgradeInsecureRequests = []
} else if (config.csp.upgradeInsecureRequests === true) {
directives.upgradeInsecureRequests = true
directives.upgradeInsecureRequests = []
}
}