@@ -118,6 +118,13 @@ public function provideRequestAndResponsesForOnKernelResponse()
118
118
$ this ->createResponse ($ responseNonceHeaders ),
119
119
array ('Content-Security-Policy ' => null , 'X-Content-Security-Policy ' => null ),
120
120
),
121
+ array (
122
+ $ nonce ,
123
+ array ('csp_script_nonce ' => $ nonce , 'csp_style_nonce ' => $ nonce ),
124
+ $ this ->createRequest (),
125
+ $ this ->createResponse (array ('Content-Security-Policy ' => 'frame-ancestors https: ; form-action: https: ' )),
126
+ array ('Content-Security-Policy ' => 'frame-ancestors https: ; form-action: https: ' , 'X-Content-Security-Policy ' => null ),
127
+ ),
121
128
array (
122
129
$ nonce ,
123
130
array ('csp_script_nonce ' => $ nonce , 'csp_style_nonce ' => $ nonce ),
@@ -130,7 +137,7 @@ public function provideRequestAndResponsesForOnKernelResponse()
130
137
array ('csp_script_nonce ' => $ nonce , 'csp_style_nonce ' => $ nonce ),
131
138
$ this ->createRequest (),
132
139
$ this ->createResponse (array ('Content-Security-Policy ' => 'script-src \'self \' \'unsafe-inline \'' )),
133
- array ('Content-Security-Policy ' => 'script-src \'self \' \'unsafe-inline \'; style-src \' unsafe-inline \' \' nonce- ' . $ nonce . '\' ' , 'X-Content-Security-Policy ' => null ),
140
+ array ('Content-Security-Policy ' => 'script-src \'self \' \'unsafe-inline \'' , 'X-Content-Security-Policy ' => null ),
134
141
),
135
142
array (
136
143
$ nonce ,
@@ -144,21 +151,21 @@ public function provideRequestAndResponsesForOnKernelResponse()
144
151
array ('csp_script_nonce ' => $ nonce , 'csp_style_nonce ' => $ nonce ),
145
152
$ this ->createRequest (),
146
153
$ this ->createResponse (array ('X-Content-Security-Policy ' => 'script-src \'self \' \'unsafe-inline \'' )),
147
- array ('X-Content-Security-Policy ' => 'script-src \'self \' \'unsafe-inline \'; style-src \' unsafe-inline \' \' nonce- ' . $ nonce . '\' ' , 'Content-Security-Policy ' => null ),
154
+ array ('X-Content-Security-Policy ' => 'script-src \'self \' \'unsafe-inline \'' , 'Content-Security-Policy ' => null ),
148
155
),
149
156
array (
150
157
$ nonce ,
151
158
array ('csp_script_nonce ' => $ nonce , 'csp_style_nonce ' => $ nonce ),
152
159
$ this ->createRequest (),
153
160
$ this ->createResponse (array ('X-Content-Security-Policy ' => 'script-src \'self \'' )),
154
- array ('X-Content-Security-Policy ' => 'script-src \'self \' \'unsafe-inline \' \'nonce- ' .$ nonce .'\'; style-src \' unsafe-inline \' \' nonce- ' . $ nonce . '\' ' , 'Content-Security-Policy ' => null ),
161
+ array ('X-Content-Security-Policy ' => 'script-src \'self \' \'unsafe-inline \' \'nonce- ' .$ nonce .'\'' , 'Content-Security-Policy ' => null ),
155
162
),
156
163
array (
157
164
$ nonce ,
158
165
array ('csp_script_nonce ' => $ nonce , 'csp_style_nonce ' => $ nonce ),
159
166
$ this ->createRequest (),
160
167
$ this ->createResponse (array ('X-Content-Security-Policy ' => 'script-src \'self \' \'unsafe-inline \' \'sha384-LALALALALAAL \'' )),
161
- array ('X-Content-Security-Policy ' => 'script-src \'self \' \'unsafe-inline \' \'sha384-LALALALALAAL \' \'nonce- ' .$ nonce .'\'; style-src \' unsafe-inline \' \' nonce- ' . $ nonce . '\' ' , 'Content-Security-Policy ' => null ),
168
+ array ('X-Content-Security-Policy ' => 'script-src \'self \' \'unsafe-inline \' \'sha384-LALALALALAAL \' \'nonce- ' .$ nonce .'\'' , 'Content-Security-Policy ' => null ),
162
169
),
163
170
array (
164
171
$ nonce ,
0 commit comments