From 65a34f5b650f10959c0f48bb097888a5fb31c6cc Mon Sep 17 00:00:00 2001 From: Josh North Date: Mon, 16 Aug 2021 10:42:45 -0400 Subject: [PATCH] CSP tweaks again, login uid fix, mild cleanup --- changeaccess.php | 4 ++-- inc/header.inc.php | 4 ++-- index.php | 4 ++-- signin.php | 4 ++-- signin_display.php | 4 ++-- signout.php | 4 ++-- 6 files changed, 12 insertions(+), 12 deletions(-) diff --git a/changeaccess.php b/changeaccess.php index 2ade07a..7d64a87 100644 --- a/changeaccess.php +++ b/changeaccess.php @@ -81,8 +81,8 @@ if ($StaticFunctions->getUserSessionStatus() == true) { // CHECK STATUS header('Location: index.php'); // ELSE HOME } else { - header("X-Frame-Options: SAMEORIGIN"); - header("X-Content-Type-Options: nosniff"); + //header("X-Frame-Options: SAMEORIGIN"); + //header("X-Content-Type-Options: nosniff"); //header("Content-Security-Policy: script-src 'self' 'unsafe-inline'; script-src-elem 'self'; script-src-attr 'self'; style-src 'self'; style-src-elem 'self'; style-src-attr 'self'; img-src 'self'; connect-src 'self'; frame-src 'self'; font-src 'self'; media-src 'self'; object-src 'self'; manifest-src 'self'; worker-src 'self'; prefetch-src 'self'; form-action 'self'; frame-ancestors 'self'; default-src 'self'", false); if (!empty(filter_input(INPUT_GET, 'a', FILTER_SANITIZE_FULL_SPECIAL_CHARS))) { //echo '
' . print_r($_POST, true) . '
'; diff --git a/inc/header.inc.php b/inc/header.inc.php index 6fa718e..3f68e64 100644 --- a/inc/header.inc.php +++ b/inc/header.inc.php @@ -84,8 +84,8 @@ $_SESSION['nonceStr'] = base64_encode(random_bytes(32)); $nonceHeader="nonce-".$_SESSION['nonceStr']; $urlsrc=basename(filter_input(INPUT_SERVER, 'PHP_SELF', FILTER_SANITIZE_URL)); - header("X-Frame-Options: SAMEORIGIN"); - header("X-Content-Type-Options: nosniff"); + //header("X-Frame-Options: SAMEORIGIN"); + //header("X-Content-Type-Options: nosniff"); //oldheader("Content-Security-Policy: default-src '$nonceHeader' 'self'; script-src '$nonceHeader' 'self' ; script-src-elem '$nonceHeader' 'self'; script-src-attr '$nonceHeader' 'self'; style-src '$nonceHeader' 'self'; style-src-elem '$nonceHeader' 'self'; style-src-attr '$nonceHeader' 'self'; img-src '$nonceHeader' 'self' data:; connect-src '$nonceHeader' 'self'; frame-src '$nonceHeader' 'self'; font-src '$nonceHeader' 'self'; media-src '$nonceHeader' 'self'; object-src '$nonceHeader' 'self'; manifest-src '$nonceHeader' 'self'; worker-src '$nonceHeader' 'self'; prefetch-src '$nonceHeader' 'self'; form-action '$nonceHeader' 'self'; frame-ancestors '$nonceHeader' 'self'"); header("Content-Security-Policy: default-src '$nonceHeader' 'self'; script-src '$nonceHeader' 'self' ; style-src '$nonceHeader' 'self'; img-src '$nonceHeader' 'self' data:; connect-src '$nonceHeader' 'self'; frame-src '$nonceHeader' 'self'; font-src '$nonceHeader' 'self'; media-src '$nonceHeader' 'self'; object-src '$nonceHeader' 'self'; manifest-src '$nonceHeader' 'self'; worker-src '$nonceHeader' 'self'; prefetch-src '$nonceHeader' 'self'; form-action '$nonceHeader' 'self'; frame-ancestors 'self'"); if (!empty($_GET['a'])) { diff --git a/index.php b/index.php index c66b317..583ac1b 100644 --- a/index.php +++ b/index.php @@ -82,8 +82,8 @@ $app_current_pageicon = ' '; require_once("inc/header.inc.php"); $urlsrc=basename(filter_input(INPUT_SERVER, 'PHP_SELF', FILTER_SANITIZE_URL)); - header("X-Frame-Options: SAMEORIGIN"); - header("X-Content-Type-Options: nosniff"); + //header("X-Frame-Options: SAMEORIGIN"); + //header("X-Content-Type-Options: nosniff"); //header("Content-Security-Policy: script-src 'self' 'unsafe-inline'; script-src-elem 'self'; script-src-attr 'self'; style-src 'self'; style-src-elem 'self'; style-src-attr 'self'; img-src 'self'; connect-src 'self'; frame-src 'self'; font-src 'self'; media-src 'self'; object-src 'self'; manifest-src 'self'; worker-src 'self'; prefetch-src 'self'; form-action 'self'; frame-ancestors 'self'; default-src 'self'", false); if (!empty($_GET['a'])) { echo '
' . print_r($_POST, true) . '
'; diff --git a/signin.php b/signin.php index f942934..c4d8b2c 100644 --- a/signin.php +++ b/signin.php @@ -53,8 +53,8 @@ if ($StaticFunctions->getSessionStatus() == true) { // CHECK STATUS header('Location: index.php'); // ELSE HOME } else { - header("X-Frame-Options: SAMEORIGIN"); - header("X-Content-Type-Options: nosniff"); + //header("X-Frame-Options: SAMEORIGIN"); + //header("X-Content-Type-Options: nosniff"); //header("Content-Security-Policy: script-src 'self' 'unsafe-inline'; script-src-elem 'self'; script-src-attr 'self'; style-src 'self'; style-src-elem 'self'; style-src-attr 'self'; img-src 'self'; connect-src 'self'; frame-src 'self'; font-src 'self'; media-src 'self'; object-src 'self'; manifest-src 'self'; worker-src 'self'; prefetch-src 'self'; form-action 'self'; frame-ancestors 'self'; default-src 'self'", false); if (!empty($_GET['a'])) { echo '
' . print_r($_POST, true) . '
'; diff --git a/signin_display.php b/signin_display.php index e9f2970..5ef9b49 100644 --- a/signin_display.php +++ b/signin_display.php @@ -54,8 +54,8 @@ if ($StaticFunctions->getSessionStatus() == true) { // CHECK STATUS header('Location: index.php'); // ELSE HOME } else { - header("X-Frame-Options: SAMEORIGIN"); - header("X-Content-Type-Options: nosniff"); + //header("X-Frame-Options: SAMEORIGIN"); + //header("X-Content-Type-Options: nosniff"); //header("Content-Security-Policy: script-src 'self' 'unsafe-inline'; script-src-elem 'self'; script-src-attr 'self'; style-src 'self'; style-src-elem 'self'; style-src-attr 'self'; img-src 'self'; connect-src 'self'; frame-src 'self'; font-src 'self'; media-src 'self'; object-src 'self'; manifest-src 'self'; worker-src 'self'; prefetch-src 'self'; form-action 'self'; frame-ancestors 'self'; default-src 'self'", false); if (!empty($_GET['a'])) { echo '
' . print_r($_POST, true) . '
'; diff --git a/signout.php b/signout.php index 78ba83d..5ed7689 100644 --- a/signout.php +++ b/signout.php @@ -54,8 +54,8 @@ if ($StaticFunctions->getSessionStatus() == true) { // CHECK STATUS header('Location: index.php'); // ELSE HOME } else { - header("X-Frame-Options: SAMEORIGIN"); - header("X-Content-Type-Options: nosniff"); + //header("X-Frame-Options: SAMEORIGIN"); + //header("X-Content-Type-Options: nosniff"); //header("Content-Security-Policy: script-src 'self' 'unsafe-inline'; script-src-elem 'self'; script-src-attr 'self'; style-src 'self'; style-src-elem 'self'; style-src-attr 'self'; img-src 'self'; connect-src 'self'; frame-src 'self'; font-src 'self'; media-src 'self'; object-src 'self'; manifest-src 'self'; worker-src 'self'; prefetch-src 'self'; form-action 'self'; frame-ancestors 'self'; default-src 'self'", false); if (!empty($_GET['a'])) { echo '
' . print_r($_POST, true) . '
';