Add X-Content-Security-Policy: sandbox
recommendation for the content repository
#866
Labels
clarification
An area where the expected behaviour is understood, but the spec could do with being more explicit
enhancement
A suggestion for a relatively simple improvement to the protocol
This is a non-standard CSP-like header supported by IE11 which only supports the
sandbox
directive. This is enough to disable script execution however and can therefore mitigate the problem of XSS in the content repository for users still using IE11.C.f. Synapse PR: matrix-org/synapse#10468
The text was updated successfully, but these errors were encountered: