Move Access-Control-Max-Age to security.conf
This commit is contained in:
parent
8293f6f1c3
commit
023e2cdad3
@ -19,8 +19,6 @@ server {
|
|||||||
|
|
||||||
add_header Cross-Origin-Resource-Policy "same-origin" always;
|
add_header Cross-Origin-Resource-Policy "same-origin" always;
|
||||||
add_header Cross-Origin-Opener-Policy "same-origin" always;
|
add_header Cross-Origin-Opener-Policy "same-origin" always;
|
||||||
proxy_hide_header Access-Control-Max-Age;
|
|
||||||
add_header Access-Control-Max-Age "600";
|
|
||||||
|
|
||||||
location / {
|
location / {
|
||||||
proxy_pass http://nextcloud:8080;
|
proxy_pass http://nextcloud:8080;
|
||||||
|
@ -10,8 +10,4 @@ add_header Cross-Origin-Opener-Policy "same-origin" always;
|
|||||||
# Change COEP to "credentialless" when supported by Safari
|
# Change COEP to "credentialless" when supported by Safari
|
||||||
# https://developer.mozilla.org/en-US/docs/Web/API/Window/credentialless
|
# https://developer.mozilla.org/en-US/docs/Web/API/Window/credentialless
|
||||||
proxy_hide_header Cross-Origin-Embedder-Policy;
|
proxy_hide_header Cross-Origin-Embedder-Policy;
|
||||||
add_header Cross-Origin-Embedder-Policy "require-corp" always;
|
add_header Cross-Origin-Embedder-Policy "require-corp" always;
|
||||||
|
|
||||||
# Access-Control-Max-Age
|
|
||||||
proxy_hide_header Access-Control-Max-Age;
|
|
||||||
add_header Access-Control-Max-Age "600";
|
|
@ -13,6 +13,10 @@ add_header X-Content-Type-Options "nosniff" always;
|
|||||||
proxy_hide_header X-Permitted-Cross-Domain-Policies;
|
proxy_hide_header X-Permitted-Cross-Domain-Policies;
|
||||||
add_header X-Permitted-Cross-Domain-Policies "none" always;
|
add_header X-Permitted-Cross-Domain-Policies "none" always;
|
||||||
|
|
||||||
|
# Access-Control-Max-Age
|
||||||
|
proxy_hide_header Access-Control-Max-Age;
|
||||||
|
add_header Access-Control-Max-Age "600";
|
||||||
|
|
||||||
# Obsolete and replaced by Content-Security-Policy frame-ancestors
|
# Obsolete and replaced by Content-Security-Policy frame-ancestors
|
||||||
# Setting the less restrictive SAMEORIGIN here, as frame-ancestors 'none' will overwrite it anyways
|
# Setting the less restrictive SAMEORIGIN here, as frame-ancestors 'none' will overwrite it anyways
|
||||||
proxy_hide_header X-Frame-Options;
|
proxy_hide_header X-Frame-Options;
|
||||||
|
Loading…
x
Reference in New Issue
Block a user