From 2138faecf95c7a0f22e6c41448d512218b5dac6a Mon Sep 17 00:00:00 2001 From: Raphael Michel Date: Sat, 17 Sep 2016 23:08:56 +0200 Subject: [PATCH] SecurityMiddleware: Increase CSP parser tolerance --- src/pretix/base/middleware.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/pretix/base/middleware.py b/src/pretix/base/middleware.py index 4d80d97c3..b244f1ecb 100644 --- a/src/pretix/base/middleware.py +++ b/src/pretix/base/middleware.py @@ -139,8 +139,8 @@ class SecurityMiddleware: def _parse_csp(self, header): h = {} for part in header.split(';'): - k, v = part.split(' ', 1) - h[k] = v + k, v = part.strip().split(' ', 1) + h[k.strip()] = v return h def _render_csp(self, h):