@@ -45,28 +45,28 @@ class ContentSecurityPolicy extends BaseConfig
45
45
/**
46
46
* Will default to self if not overridden
47
47
*
48
- * @var string|string[] |null
48
+ * @var list< string> |string|null
49
49
*/
50
50
public $ defaultSrc ;
51
51
52
52
/**
53
53
* Lists allowed scripts' URLs.
54
54
*
55
- * @var string|string[]
55
+ * @var list< string> |string
56
56
*/
57
57
public $ scriptSrc = 'self ' ;
58
58
59
59
/**
60
60
* Lists allowed stylesheets' URLs.
61
61
*
62
- * @var string|string[]
62
+ * @var list< string> |string
63
63
*/
64
64
public $ styleSrc = 'self ' ;
65
65
66
66
/**
67
67
* Defines the origins from which images can be loaded.
68
68
*
69
- * @var string|string[]
69
+ * @var list< string> |string
70
70
*/
71
71
public $ imageSrc = 'self ' ;
72
72
@@ -75,36 +75,36 @@ class ContentSecurityPolicy extends BaseConfig
75
75
*
76
76
* Will default to self if not overridden
77
77
*
78
- * @var string|string[] |null
78
+ * @var list< string> |string|null
79
79
*/
80
80
public $ baseURI ;
81
81
82
82
/**
83
83
* Lists the URLs for workers and embedded frame contents
84
84
*
85
- * @var string|string[]
85
+ * @var list< string> |string
86
86
*/
87
87
public $ childSrc = 'self ' ;
88
88
89
89
/**
90
90
* Limits the origins that you can connect to (via XHR,
91
91
* WebSockets, and EventSource).
92
92
*
93
- * @var string|string[]
93
+ * @var list< string> |string
94
94
*/
95
95
public $ connectSrc = 'self ' ;
96
96
97
97
/**
98
98
* Specifies the origins that can serve web fonts.
99
99
*
100
- * @var string|string[]
100
+ * @var list< string> |string
101
101
*/
102
102
public $ fontSrc ;
103
103
104
104
/**
105
105
* Lists valid endpoints for submission from `<form>` tags.
106
106
*
107
- * @var string|string[]
107
+ * @var list< string> |string
108
108
*/
109
109
public $ formAction = 'self ' ;
110
110
@@ -114,48 +114,48 @@ class ContentSecurityPolicy extends BaseConfig
114
114
* and `<applet>` tags. This directive can't be used in
115
115
* `<meta>` tags and applies only to non-HTML resources.
116
116
*
117
- * @var string|string[] |null
117
+ * @var list< string> |string|null
118
118
*/
119
119
public $ frameAncestors ;
120
120
121
121
/**
122
122
* The frame-src directive restricts the URLs which may
123
123
* be loaded into nested browsing contexts.
124
124
*
125
- * @var array |string|null
125
+ * @var list<string> |string|null
126
126
*/
127
127
public $ frameSrc ;
128
128
129
129
/**
130
130
* Restricts the origins allowed to deliver video and audio.
131
131
*
132
- * @var string|string[] |null
132
+ * @var list< string> |string|null
133
133
*/
134
134
public $ mediaSrc ;
135
135
136
136
/**
137
137
* Allows control over Flash and other plugins.
138
138
*
139
- * @var string|string[]
139
+ * @var list< string> |string
140
140
*/
141
141
public $ objectSrc = 'self ' ;
142
142
143
143
/**
144
- * @var string|string[] |null
144
+ * @var list< string> |string|null
145
145
*/
146
146
public $ manifestSrc ;
147
147
148
148
/**
149
149
* Limits the kinds of plugins a page may invoke.
150
150
*
151
- * @var string|string[] |null
151
+ * @var list< string> |string|null
152
152
*/
153
153
public $ pluginTypes ;
154
154
155
155
/**
156
156
* List of actions allowed.
157
157
*
158
- * @var string|string[] |null
158
+ * @var list< string> |string|null
159
159
*/
160
160
public $ sandbox ;
161
161
0 commit comments