File tree Expand file tree Collapse file tree 2 files changed +2
-2
lines changed
Expand file tree Collapse file tree 2 files changed +2
-2
lines changed Original file line number Diff line number Diff line change @@ -10,7 +10,7 @@ AddDefaultCharset UTF-8
1010 #
1111 ### Only works in Apache 2.4.10+ (Reason, condition -> "expr = -z% {resp: ...}") ###
1212 #
13- Header always set Content-Security-Policy "object-src 'none';frame-ancestors 'none';base-uri 'none';form-action 'self'" "expr=-z %{resp:Content-Security-Policy}"
13+ Header always set Content-Security-Policy "default-src 'self'; object-src 'none';frame-ancestors 'none';base-uri 'none';form-action 'self'" "expr=-z %{resp:Content-Security-Policy}"
1414 Header always set Feature-Policy "accelerometer 'none';ambient-light-sensor 'none';autoplay 'none';battery 'none';camera 'none';document-domain 'self';fullscreen 'self';geolocation 'none';gyroscope 'none';magnetometer 'none';microphone 'none';midi 'none';payment 'none';picture-in-picture 'none';sync-xhr 'self';usb 'none'" "expr=-z %{resp:Feature-Policy}"
1515 Header always set Referrer-Policy "strict-origin-when-cross-origin" "expr=-z %{resp:Referrer-Policy}"
1616# for https only mode
Original file line number Diff line number Diff line change @@ -11,7 +11,7 @@ server {
1111 charset utf-8;
1212 server_tokens off;
1313
14- add_header Content-Security-Policy "object-src 'none';frame-ancestors 'none';base-uri 'none';form-action 'self'" always;
14+ add_header Content-Security-Policy "default-src 'self'; object-src 'none';frame-ancestors 'none';base-uri 'none';form-action 'self'" always;
1515 add_header Feature-Policy "accelerometer 'none';ambient-light-sensor 'none';autoplay 'none';battery 'none';camera 'none';document-domain 'self';fullscreen 'self';geolocation 'none';gyroscope 'none';magnetometer 'none';microphone 'none';midi 'none';payment 'none';picture-in-picture 'none';sync-xhr 'self';usb 'none'" always;
1616 add_header Referrer-Policy "strict-origin-when-cross-origin" always;
1717# add_header Strict-Transport-Security "max-age=31536000" always; # for https only
You can’t perform that action at this time.
0 commit comments