We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 5d10e4c commit 6f9d68fCopy full SHA for 6f9d68f
nginx/conf.d/headers.txt
@@ -5,4 +5,4 @@ add_header Strict-Transport-Security "max-age=31536000; includeSubDomains";
5
add_header Permissions-Policy "accelerometer=(), autoplay=(), camera=(), encrypted-media=(), fullscreen=(self), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), usb=()";
6
add_header X-XSS-Protection "1; mode=block";
7
# You should harden the 'connect-src' to your PxWebApi address
8
-add_header Content-Security-Policy "default-src 'none'; script-src 'self'; connect-src 'self' https:; style-src 'self'; img-src 'self'; font-src 'self'; object-src 'none'; frame-ancestors 'self'; base-uri 'self';";
+add_header Content-Security-Policy "default-src 'none'; script-src 'self'; connect-src 'self' http:; style-src 'self'; img-src 'self'; font-src 'self'; object-src 'none'; frame-ancestors 'self'; base-uri 'self';";
0 commit comments