NGINX-Configs/etc/nginx/snippets/cross-origin-security.conf

11 lines
454 B
Plaintext
Raw Normal View History

# CORP, COOP, and COEP headers
# Meant to be used globally, but some apps may need a manual overwrite, so this is split out from security.conf
proxy_hide_header Cross-Origin-Resource-Policy;
add_header Cross-Origin-Resource-Policy cross-origin always;
proxy_hide_header Cross-Origin-Opener-Policy;
add_header Cross-Origin-Opener-Policy same-origin always;
proxy_hide_header Cross-Origin-Opener-Policy;
Cross-Origin-Embedder-Policy require-corp always;