Bug#1040996: Davical defines a Content-Security-Policy without scoping it to its own resources

2023-10-25 Thread Andrew Ruthven
Hi Alain, Thanks for the bug report. I have added a fix to DAViCal so the CSP is only applied to the Directory as suggested. I'm looking at your .well-known request, but I don't think DAViCal and NextCloud can co-exist so easily as it looks like they both have overlapping well-known paths. I

Bug#1040996: Davical defines a Content-Security-Policy without scoping it to its own resources

2023-07-13 Thread Alain Knaff
Package: davical Version: 1.1.12-2 Hi, At the end of its example / reference configuration file /etc/apache2/sites-available/davical.conf, davical defines a Content-Security-Policy, but forgets to bracket it with instructions to scope it to its own resources. Should be: Header set