3bacf54b6a23bc56f728c2e670c9b2cca96222dd max Wed Sep 16 04:56:02 2026 -0700 htmshell: drop the two CSP response-header helpers that no longer have callers, refs #38353 cspWriteResponseHeader() was their only user and it queues the policy through cgiAddHttpHeader() now, so generateCspResponseHeader() and getCspMetaResponseHeader() build a header line nothing sends. Neither had another caller at any point. The meta-tag side is untouched. diff --git src/lib/htmshell.c src/lib/htmshell.c index d8655157a9e..cefcb2de0e0 100644 --- src/lib/htmshell.c +++ src/lib/htmshell.c @@ -1097,66 +1097,47 @@ dyStringAppend(policy, " stats.g.doubleclick.net"); // used by google analytics dyStringAppend(policy, ";"); */ return dyStringCannibalize(&policy); } char *getCspMetaString(char *policy) /* get the policy string as an html header meta tag */ { char meta[4096]; safef(meta, sizeof meta, "\n", policy); // use double quotes around policy because it contains single-quoted values. return cloneString(meta); } -char *getCspMetaResponseHeader(char *policy) -/* get the policy string as an http response header */ -{ -char response[4096]; -safef(response, sizeof response, "Content-Security-Policy: %s\n", policy); -return cloneString(response); -} - char *getCspMetaHeader() /* return meta CSP header string */ { char *policy = getCspPolicyString(); char *meta = getCspMetaString(policy); freeMem(policy); return meta; } void generateCspMetaHeader(FILE *f) /* generate meta CSP header */ { char *meta = getCspMetaHeader(); fputs(meta, f); freeMem(meta); } -void generateCspResponseHeader(FILE *f) -/* generate the CSP as an http response header. Carries the same nonce as the - * meta tag, since getNonce() is one-per-process, so a page may safely have both. - * Must be called before the blank line that ends the http header block. */ -{ -char *policy = getCspPolicyString(); -char *header = getCspMetaResponseHeader(policy); -fputs(header, f); -freeMem(header); -freeMem(policy); -} void _htmStartWithHead(FILE *f, char *head, char *title, boolean printDocType, int dirDepth) /* Write out bits of header that both stand-alone .htmls * and CGI returned .htmls need, including optional head info */ { if (printDocType) fputs("\n",f); if (doNotTranslate) fputs("\n", f); // switches off auto-translation question else fputs("\n", f);