Commit 75dc2e2a authored by Alex Wiens's avatar Alex Wiens
Browse files

element-web: Set CSP frame-ancestors to 'self' to repair download links for encrypted media

See https://github.com/vector-im/element-web/issues/16774 for more details
parent e6b18aa3
......@@ -14,6 +14,6 @@ server {
add_header X-Frame-Options SAMEORIGIN;
add_header X-Content-Type-Options nosniff;
add_header X-XSS-Protection "1; mode=block";
add_header Content-Security-Policy "frame-ancestors 'none'";
add_header Content-Security-Policy "frame-ancestors 'self'";
}
}
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment