Enforce referrer-policy in WebUI

This stops leaking private data to other websites via Referrer header.
This commit is contained in:
Chocobo1 2018-12-10 22:14:53 +08:00
parent e1f19b7c75
commit 7fd30fa90f
No known key found for this signature in database
GPG key ID: 210D9C873253A68C
2 changed files with 4 additions and 1 deletions

View file

@ -570,9 +570,11 @@ Http::Response WebApplication::processRequest(const Http::Request &request, cons
if (m_isHttpsEnabled) {
csp += QLatin1String(" upgrade-insecure-requests;");
}
header(Http::HEADER_CONTENT_SECURITY_POLICY, csp);
if (!m_isAltUIUsed)
header(Http::HEADER_REFERRER_POLICY, "same-origin");
return response();
}