Files
bpfire/config/httpd
Peter Müller eb6d71514a prevent loading resources from external sites
Make Apache transmit a CSP (Content Security Policy) header
for WebUI and Captive Portal contents.

This prevents some XSS and content injection attacks, especially
in case no transport encryption (Captive Portal!) can be used.

Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-12-16 12:18:39 +00:00
..
2017-09-04 12:40:20 +01:00
2006-09-18 19:05:20 +00:00
2017-09-04 12:40:20 +01:00
2006-09-18 19:05:20 +00:00
2017-09-04 12:40:20 +01:00
2017-09-04 12:40:20 +01:00
2006-09-18 19:05:20 +00:00