From 1b8b19d08a2022563c06721148c44fd1990eb5c7 Mon Sep 17 00:00:00 2001 From: Alfred Egger Date: Wed, 6 Nov 2019 15:20:21 +0100 Subject: [PATCH] Add CSP exception for Angular.js --- lib/Controller/CityController.php | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/lib/Controller/CityController.php b/lib/Controller/CityController.php index 3d81f26..19145cc 100644 --- a/lib/Controller/CityController.php +++ b/lib/Controller/CityController.php @@ -43,7 +43,15 @@ class CityController extends IntermediateController { * @NoCSRFRequired */ public function index () { - return new TemplateResponse($this->appName, 'main'); + $response = new TemplateResponse($this->appName, 'main'); // templates/main.php + + $csp = new StrictContentSecurityPolicy(); + $csp->allowEvalScript(); + $csp->allowInlineStyle(); + + $response->setContentSecurityPolicy($csp); + + return $response; } /**