Branch: refs/heads/1.6.0
Home:
https://github.com/tribe29/checkmk
Commit: be02dc40e02b541c0540ccf14f91f76d48b77cc3
https://github.com/tribe29/checkmk/commit/be02dc40e02b541c0540ccf14f91f76d4…
Author: Lars Michelsen <lm(a)tribe29.com>
Date: 2020-01-27 (Mon, 27 Jan 2020)
Changed paths:
M omd/packages/apache-omd/skel/etc/apache/conf.d/security.conf
Log Message:
-----------
Setting CSP header in expected format
Previous releases used the "," separator to concatenate the different
parts of the content security policy header. This was done using the
apache mod_headers "append" header mechanism. The main reason to do so
was that this is more readable in the apache configuration than setting
a header with a single long value.
Sadly this "," separator is not used as separator of the CSP header
which makes browsers misunderstand the configuration.
We now set a single header with ";" as separator which makes the
browsers understand the policy as intended.
Change-Id: Ide0207908c4f84d8decf0bc4e0a91a030d80b3bf