summaryrefslogtreecommitdiffstats
path: root/src
diff options
context:
space:
mode:
authorSamantaz Fox <coding@samantaz.fr>2021-06-20 18:43:00 +0200
committerGitHub <noreply@github.com>2021-06-20 18:43:00 +0200
commit5a8825d01682def020acfd2baf95a44b94790f6f (patch)
tree772f180f1570edd645e5450047c1c12d4f1d6233 /src
parente6bdcff0dd55d71af92c55958487a5aa0006edf3 (diff)
downloadinvidious-5a8825d01682def020acfd2baf95a44b94790f6f.tar.gz
invidious-5a8825d01682def020acfd2baf95a44b94790f6f.tar.bz2
invidious-5a8825d01682def020acfd2baf95a44b94790f6f.zip
Fix quoting of 'none' in CSP header
The keyword 'none' must be surrounded by single quotes. Regression introduced by #2168.
Diffstat (limited to 'src')
-rw-r--r--src/invidious.cr2
1 files changed, 1 insertions, 1 deletions
diff --git a/src/invidious.cr b/src/invidious.cr
index b1ee1525..f7c8980a 100644
--- a/src/invidious.cr
+++ b/src/invidious.cr
@@ -187,7 +187,7 @@ before_all do |env|
if env.request.resource.starts_with?("/embed")
frame_ancestors = "'self' http: https:"
else
- frame_ancestors = "none"
+ frame_ancestors = "'none'"
end
# TODO: Remove style-src's 'unsafe-inline', requires to remove all