-
-
Notifications
You must be signed in to change notification settings - Fork 4.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
"Content-Security-Policy" with CloudFlare persists in version 14 (Beta) #10557
Comments
As stated in #4840 this is indeed unsupported and will most likely break. On top of that this means that cloudflare can do MITM attacks as you allow it to rewrite your html. |
@rullzer Cloudflare is a legitimate CDN service, why would you flag them to impersonate with MITM attack? |
I'm not saying they are doing it. I'm saying they can do it in your setup. Which is something you should not want with your data. |
|
with DNS behind cloudflare, the same issue of "Content-Security-Policy" is again present in version 14 Beta.
-->
Steps to reproduce
Actual behavior
see attached image and similarly to this previous version issue (#4840)
Server configuration
Operating system:
Debian Stretch 9
Web server:
NGINX 1.12
Database:
MariaDB
PHP version:
PHP7.0
Nextcloud version: (see Nextcloud admin page)
Nextcloud Beta 1
Updated from an older Nextcloud/ownCloud or fresh install:
Fresh Installation
Where did you install Nextcloud from:
Official nextcloud web page
this image show the problem
The text was updated successfully, but these errors were encountered: