From 8b8da74d2e3cdb65b3ed7a2f6dff929a4b20f5cc Mon Sep 17 00:00:00 2001 From: Edwin Lyon <53972157+practical-engelbart@users.noreply.github.com> Date: Thu, 5 Nov 2020 16:12:13 -0800 Subject: [PATCH] Update headers.conf --- nginx/snippets/headers.conf | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/nginx/snippets/headers.conf b/nginx/snippets/headers.conf index 183e078..21bb2a7 100644 --- a/nginx/snippets/headers.conf +++ b/nginx/snippets/headers.conf @@ -1,6 +1,5 @@ add_header Cache-Control "no-transform"; -add_header X-XSS-Protection "1; mode=block"; -add_header Referrer-Policy "no-referrer"; add_header X-UA-Compatible "IE=Edge"; -add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' https://*.example.com https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https://fonts.googleapi.com https://cdnjs.cloudflare.com https://*.example.com; img-src * data: https:; font-src 'self' data: https: https://*.example.com https://cdnjs.cloudflare.com https://fonts.gstatic.com; object-src 'none'; frame-src *; frame-ancestors 'self'; upgrade-insecure-requests"; -add_header Feature-Policy "accelerometer 'none'; ambient-light-sensor 'none'; autoplay 'none'; camera 'none'; encrypted-media 'self'; fullscreen 'self'; geolocation 'none'; gyroscope 'none'; magnetometer 'none'; microphone 'none'; midi 'none'; payment 'none'; picture-in-picture 'none'; sync-xhr 'self' https://haveibeenpwned.com https://twofactorauth.org; usb 'none'; vr 'none'"; +add_header Content-Security-Policy "default-src 'self'; base-uri 'none'; object-src 'none'; manifest-src 'self'; script-src 'self' 'unsafe-inline' https://email.example.com https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https://email.example.com https://cdnjs.cloudflare.com; img-src 'self' data: https: blob:; font-src 'self' data: https:; connect-src 'self'; media-src 'self'; frame-ancestors 'self'; worker-src 'self' blob:; upgrade-insecure-requests"; +add_header Feature-Policy "accelerometer 'none'; ambient-light-sensor 'self'; autoplay 'none'; camera 'none'; encrypted-media 'self'; fullscreen 'self'; geolocation 'self'; gyroscope 'none'; magnetometer 'none'; microphone 'none'; midi 'none'; payment 'none'; picture-in-picture 'self'; speaker 'none'; sync-xhr 'self' https://haveibeenpwned.com https://twofactorauth.org; usb 'self'; vr 'none'"; +add_header Permissions-Policy "geolocation=(self);midi=();notifications=(self);push=(self);sync-xhr=(self);microphone=();camera=();magnetometer=();gyroscope=();speaker=(self);vibrate=();fullscreen=(self);payment=()";