Ignore form action when doing oAuth2.

This commit is contained in:
James Cole 2019-01-27 17:15:40 +01:00
parent cec8210d8b
commit 20b458f35d

View File

@ -54,12 +54,15 @@ class SecureHeaders
sprintf("script-src 'self' 'unsafe-eval' 'unsafe-inline' %s", $google),
"style-src 'self' 'unsafe-inline'",
"base-uri 'self'",
"form-action 'self'",
"font-src 'self'",
"connect-src 'self'",
"img-src 'self' data: https://api.tiles.mapbox.com",
"manifest-src 'self'",
];
$route = $request->route()->uri;
if($route !== 'oauth/authorize') {
$csp[] = "form-action 'self'";
}
$featurePolicies = [
"geolocation 'none'",