@@ -45,28 +45,28 @@ class ContentSecurityPolicy extends BaseConfig
4545 /**
4646 * Will default to self if not overridden
4747 *
48- * @var string|string[] |null
48+ * @var list< string> |string|null
4949 */
5050 public $ defaultSrc ;
5151
5252 /**
5353 * Lists allowed scripts' URLs.
5454 *
55- * @var string|string[]
55+ * @var list< string> |string
5656 */
5757 public $ scriptSrc = 'self ' ;
5858
5959 /**
6060 * Lists allowed stylesheets' URLs.
6161 *
62- * @var string|string[]
62+ * @var list< string> |string
6363 */
6464 public $ styleSrc = 'self ' ;
6565
6666 /**
6767 * Defines the origins from which images can be loaded.
6868 *
69- * @var string|string[]
69+ * @var list< string> |string
7070 */
7171 public $ imageSrc = 'self ' ;
7272
@@ -75,36 +75,36 @@ class ContentSecurityPolicy extends BaseConfig
7575 *
7676 * Will default to self if not overridden
7777 *
78- * @var string|string[] |null
78+ * @var list< string> |string|null
7979 */
8080 public $ baseURI ;
8181
8282 /**
8383 * Lists the URLs for workers and embedded frame contents
8484 *
85- * @var string|string[]
85+ * @var list< string> |string
8686 */
8787 public $ childSrc = 'self ' ;
8888
8989 /**
9090 * Limits the origins that you can connect to (via XHR,
9191 * WebSockets, and EventSource).
9292 *
93- * @var string|string[]
93+ * @var list< string> |string
9494 */
9595 public $ connectSrc = 'self ' ;
9696
9797 /**
9898 * Specifies the origins that can serve web fonts.
9999 *
100- * @var string|string[]
100+ * @var list< string> |string
101101 */
102102 public $ fontSrc ;
103103
104104 /**
105105 * Lists valid endpoints for submission from `<form>` tags.
106106 *
107- * @var string|string[]
107+ * @var list< string> |string
108108 */
109109 public $ formAction = 'self ' ;
110110
@@ -114,48 +114,48 @@ class ContentSecurityPolicy extends BaseConfig
114114 * and `<applet>` tags. This directive can't be used in
115115 * `<meta>` tags and applies only to non-HTML resources.
116116 *
117- * @var string|string[] |null
117+ * @var list< string> |string|null
118118 */
119119 public $ frameAncestors ;
120120
121121 /**
122122 * The frame-src directive restricts the URLs which may
123123 * be loaded into nested browsing contexts.
124124 *
125- * @var array |string|null
125+ * @var list<string> |string|null
126126 */
127127 public $ frameSrc ;
128128
129129 /**
130130 * Restricts the origins allowed to deliver video and audio.
131131 *
132- * @var string|string[] |null
132+ * @var list< string> |string|null
133133 */
134134 public $ mediaSrc ;
135135
136136 /**
137137 * Allows control over Flash and other plugins.
138138 *
139- * @var string|string[]
139+ * @var list< string> |string
140140 */
141141 public $ objectSrc = 'self ' ;
142142
143143 /**
144- * @var string|string[] |null
144+ * @var list< string> |string|null
145145 */
146146 public $ manifestSrc ;
147147
148148 /**
149149 * Limits the kinds of plugins a page may invoke.
150150 *
151- * @var string|string[] |null
151+ * @var list< string> |string|null
152152 */
153153 public $ pluginTypes ;
154154
155155 /**
156156 * List of actions allowed.
157157 *
158- * @var string|string[] |null
158+ * @var list< string> |string|null
159159 */
160160 public $ sandbox ;
161161
0 commit comments