|
|
@ -43,7 +43,7 @@ server { |
|
|
|
add_header X-XSS-Protection "1; mode=block" always; |
|
|
|
add_header X-XSS-Protection "1; mode=block" always; |
|
|
|
add_header X-Frame-Options "SAMEORIGIN" always; |
|
|
|
add_header X-Frame-Options "SAMEORIGIN" always; |
|
|
|
add_header Referrer-Policy "no-referrer-when-downgrade" always; |
|
|
|
add_header Referrer-Policy "no-referrer-when-downgrade" always; |
|
|
|
add_header Content-Security-Policy "default-src 'none'; img-src 'self' 'http://www.w3.org'; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; connect-src 'self'; child-src 'self'; frame-src 'self'; frame-ancestors 'self';" always; |
|
|
|
add_header Content-Security-Policy "default-src 'self'; img-src 'self' https://www.w3.org; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; object-src 'none'; connect-src 'self'; child-src 'self'; frame-src 'self'; frame-ancestors 'self';" always; |
|
|
|
add_header Permissions-Policy "accelerometer=(), magnetometer=(), gyroscope=(), geolocation=(), midi=(), payment=(), camera=(), microphone=(), interest-cohort=()" always; |
|
|
|
add_header Permissions-Policy "accelerometer=(), magnetometer=(), gyroscope=(), geolocation=(), midi=(), payment=(), camera=(), microphone=(), interest-cohort=()" always; |
|
|
|
add_header Feature-Policy "accelerometer 'none'; magnetometer 'none'; gyroscope 'none'; geolocation 'none'; midi 'none'; payment 'none'; camera 'none'; microphone 'none';" always; |
|
|
|
add_header Feature-Policy "accelerometer 'none'; magnetometer 'none'; gyroscope 'none'; geolocation 'none'; midi 'none'; payment 'none'; camera 'none'; microphone 'none';" always; |
|
|
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; |
|
|
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; |
|
|
|