Object/Trait

net.liftweb.http

ContentSourceRestriction

Related Docs: trait ContentSourceRestriction | package http

Permalink

object ContentSourceRestriction

Linear Supertypes
Ordering
  1. Alphabetic
  2. By inheritance
Inherited
  1. ContentSourceRestriction
  2. AnyRef
  3. Any
  1. Hide All
  2. Show all
Visibility
  1. Public
  2. All

Type Members

  1. case class Host(hostAndPath: String) extends GeneralSourceRestriction with Product with Serializable

    Permalink

    Indicates content from the given host path is allowed.

    Indicates content from the given host path is allowed. See the Content-Security-Policy spec's matching rules for host-source for more about what this can look like.

    Example:

    Host("https://base.*.example.com")
  2. case class Scheme(scheme: String) extends GeneralSourceRestriction with Product with Serializable

    Permalink

    Indicates content from the given scheme is allowed.

    Indicates content from the given scheme is allowed. The scheme should not include the trailing :.

    Example:

    Scheme("data")

Value Members

  1. final def !=(arg0: Any): Boolean

    Permalink
    Definition Classes
    AnyRef → Any
  2. final def ##(): Int

    Permalink
    Definition Classes
    AnyRef → Any
  3. final def ==(arg0: Any): Boolean

    Permalink
    Definition Classes
    AnyRef → Any
  4. object All extends GeneralSourceRestriction with Product with Serializable

    Permalink

    Indicates content from all sources is allowed.

  5. object None extends GeneralSourceRestriction with Product with Serializable

    Permalink

    Indicates content from no sources is allowed.

  6. object Self extends GeneralSourceRestriction with Product with Serializable

    Permalink

    Indicates content from the same origin as the content is allowed.

  7. object UnsafeEval extends JavaScriptSourceRestriction with Product with Serializable

    Permalink

    Indicates eval and related functionality can be used.

    Indicates eval and related functionality can be used. Some of Lift's functionality, including idMemoize and comet handling, relies on eval, so not including this in your script sources will mean you won't be able to use those.

    If not specified for JavaScript, invoking eval, the Function constructor, or setTimeout/setInterval with a string parameter will all throw security exceptions in a browser that supports content security policies.

  8. object UnsafeInline extends JavaScriptSourceRestriction with StylesheetSourceRestriction with Product with Serializable

    Permalink

    Indicates inline content on the page is allowed to be interpreted.

    Indicates inline content on the page is allowed to be interpreted. It is highly recommended that this not be used, as it exposes your application to cross-site scripting and other vulnerabilities.

    If not specified for JavaScript, JavaScript on* event handler attributes, <script> elements, and javascript: URIs will not be executed by a browser that supports content security policies.

    If not specified for stylesheets, <style> elements and inline style attributes will not be read by a browser that supports content security policies.

  9. final def asInstanceOf[T0]: T0

    Permalink
    Definition Classes
    Any
  10. def clone(): AnyRef

    Permalink
    Attributes
    protected[java.lang]
    Definition Classes
    AnyRef
    Annotations
    @throws( ... )
  11. final def eq(arg0: AnyRef): Boolean

    Permalink
    Definition Classes
    AnyRef
  12. def equals(arg0: Any): Boolean

    Permalink
    Definition Classes
    AnyRef → Any
  13. def finalize(): Unit

    Permalink
    Attributes
    protected[java.lang]
    Definition Classes
    AnyRef
    Annotations
    @throws( classOf[java.lang.Throwable] )
  14. final def getClass(): Class[_]

    Permalink
    Definition Classes
    AnyRef → Any
  15. def hashCode(): Int

    Permalink
    Definition Classes
    AnyRef → Any
  16. final def isInstanceOf[T0]: Boolean

    Permalink
    Definition Classes
    Any
  17. final def ne(arg0: AnyRef): Boolean

    Permalink
    Definition Classes
    AnyRef
  18. final def notify(): Unit

    Permalink
    Definition Classes
    AnyRef
  19. final def notifyAll(): Unit

    Permalink
    Definition Classes
    AnyRef
  20. final def synchronized[T0](arg0: ⇒ T0): T0

    Permalink
    Definition Classes
    AnyRef
  21. def toString(): String

    Permalink
    Definition Classes
    AnyRef → Any
  22. final def wait(): Unit

    Permalink
    Definition Classes
    AnyRef
    Annotations
    @throws( ... )
  23. final def wait(arg0: Long, arg1: Int): Unit

    Permalink
    Definition Classes
    AnyRef
    Annotations
    @throws( ... )
  24. final def wait(arg0: Long): Unit

    Permalink
    Definition Classes
    AnyRef
    Annotations
    @throws( ... )

Inherited from AnyRef

Inherited from Any

Ungrouped