Move Access-Control-Max-Age to security.conf

This commit is contained in:
Tommy
2025-01-03 09:31:47 -07:00
committed by GitHub
parent 8293f6f1c3
commit 023e2cdad3
3 changed files with 5 additions and 7 deletions

View File

@@ -10,8 +10,4 @@ add_header Cross-Origin-Opener-Policy "same-origin" always;
# Change COEP to "credentialless" when supported by Safari
# https://developer.mozilla.org/en-US/docs/Web/API/Window/credentialless
proxy_hide_header Cross-Origin-Embedder-Policy;
add_header Cross-Origin-Embedder-Policy "require-corp" always;
# Access-Control-Max-Age
proxy_hide_header Access-Control-Max-Age;
add_header Access-Control-Max-Age "600";
add_header Cross-Origin-Embedder-Policy "require-corp" always;

View File

@@ -13,6 +13,10 @@ add_header X-Content-Type-Options "nosniff" always;
proxy_hide_header X-Permitted-Cross-Domain-Policies;
add_header X-Permitted-Cross-Domain-Policies "none" always;
# Access-Control-Max-Age
proxy_hide_header Access-Control-Max-Age;
add_header Access-Control-Max-Age "600";
# Obsolete and replaced by Content-Security-Policy frame-ancestors
# Setting the less restrictive SAMEORIGIN here, as frame-ancestors 'none' will overwrite it anyways
proxy_hide_header X-Frame-Options;