[v8.3.x] Sync security changes (#45067)
* "Release: Updated versions in package to 8.3.5" * [v8.3.x] Fix for CVE-2022-21702 (#225) Fix for CVE-2022-21702 * Update yarn.lock for 8.3.5 * resolve conflicts (cherry picked from commit bb38cfcba4b4f824060ff385d858c63f50b72d74) * csrf checks for v8.3.5 (#234) * Fix lint * Cherry pick e2e test server changes Co-authored-by: Marcus Efraimsson <marcus.efraimsson@gmail.com> Co-authored-by: Kevin Minehart <kmineh0151@gmail.com> Co-authored-by: Serge Zaitsev <serge.zaitsev@grafana.com>
This commit is contained in:
co-authored by
Marcus Efraimsson
Kevin Minehart
Serge Zaitsev
parent
667f884db1
commit
f42d0b9beb
@@ -42,3 +42,9 @@ func ClearCookieHeader(req *http.Request, keepCookiesNames []string) {
|
||||
req.AddCookie(c)
|
||||
}
|
||||
}
|
||||
|
||||
// SetProxyResponseHeaders sets proxy response headers.
|
||||
// Sets Content-Security-Policy: sandbox
|
||||
func SetProxyResponseHeaders(header http.Header) {
|
||||
header.Set("Content-Security-Policy", "sandbox")
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user