编辑phpmyadmin/libraries/Header.class.php
header(
"X-Content-Security-Policy: default-src 'self' "
. $captcha_url
. $GLOBALS['cfg']['CSPAllow'] . ';'
. "options inline-script eval-script;"
. "img-src *"
. $GLOBALS['cfg']['CSPAllow']
. $map_tile_urls
. $captcha_url
. ";"
);
header(
"X-WebKit-CSP: default-src 'self' "
. $captcha_url
. $GLOBALS['cfg']['CSPAllow'] . ';'
. "script-src 'self' "
. $captcha_url
. $GLOBALS['cfg']['CSPAllow']
. " 'unsafe-inline' 'unsafe-eval';"
. "style-src 'self' 'unsafe-inline' "
. $captcha_url
. ';'
. "img-src 'self' data: "
. $GLOBALS['cfg']['CSPAllow']
. $map_tile_urls
. $captcha_url
. ";"
); 注意 X-Content-Security-Policy 章节中 “img-src” 参数,改为 "img-src *"

本文详细介绍了如何在PHPMyAdmin中配置Content Security Policy (CSP),通过编辑Header.class.php文件来设置各种CSP指令,确保网站内容的安全加载,特别关注了img-src参数的设置。

761

被折叠的 条评论
为什么被折叠?



