fixed security hole that allowed web console in monitor mode

This commit is contained in:
John Karabudak 2020-02-13 21:59:58 -03:30
parent 5cbe0ba2b7
commit c7785ce672
1 changed files with 4 additions and 0 deletions

View File

@ -2,6 +2,10 @@
require_once 'config.php';
require_once RASPI_CONFIG.'/raspap.php';
if (RASPI_MONITOR_ENABLED) {
die();
};
session_start();
header('X-Frame-Options: SAMEORIGIN');
header("Content-Security-Policy: default-src 'none'; frame-src 'self'; connect-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'");