diff --git a/nginx/snippets/headers.conf b/nginx/snippets/headers.conf index 1896e36..0c2ede7 100644 --- a/nginx/snippets/headers.conf +++ b/nginx/snippets/headers.conf @@ -1,6 +1,5 @@ -add_header Referrer-Policy 'no-referrer'; -add_header X-Content-Type-Options "nosniff" always; -add_header X-Frame-Options SAMEORIGIN always; -add_header X-XSS-Protection "1; mode=block" always; -add_header Content-Security-Policy "upgrade-insecure-requests"; +add_header X-XSS-Protection "1; mode=block"; +add_header Referrer-Policy "no-referrer"; +add_header Content-Security-Policy "upgrade-insecure-requests"; +add_header Permissions-Policy "geolocation=();midi=();notifications=(self);push=(self);sync-xhr=();microphone=();camera=();magnetometer=();gyroscope=();speaker=(self);vibrate=();fullscreen=(self);payment=();";