Move Access-Control-Max-Age to security.conf
This commit is contained in:
		@@ -19,8 +19,6 @@ server {
 | 
				
			|||||||
 | 
					
 | 
				
			||||||
    add_header Cross-Origin-Resource-Policy "same-origin" always;
 | 
					    add_header Cross-Origin-Resource-Policy "same-origin" always;
 | 
				
			||||||
    add_header Cross-Origin-Opener-Policy "same-origin" always;
 | 
					    add_header Cross-Origin-Opener-Policy "same-origin" always;
 | 
				
			||||||
    proxy_hide_header Access-Control-Max-Age;
 | 
					 | 
				
			||||||
    add_header Access-Control-Max-Age "600";
 | 
					 | 
				
			||||||
 | 
					
 | 
				
			||||||
    location / {
 | 
					    location / {
 | 
				
			||||||
        proxy_pass http://nextcloud:8080;
 | 
					        proxy_pass http://nextcloud:8080;
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -10,8 +10,4 @@ add_header Cross-Origin-Opener-Policy "same-origin" always;
 | 
				
			|||||||
# Change COEP to "credentialless" when supported by Safari
 | 
					# Change COEP to "credentialless" when supported by Safari
 | 
				
			||||||
# https://developer.mozilla.org/en-US/docs/Web/API/Window/credentialless
 | 
					# https://developer.mozilla.org/en-US/docs/Web/API/Window/credentialless
 | 
				
			||||||
proxy_hide_header Cross-Origin-Embedder-Policy;
 | 
					proxy_hide_header Cross-Origin-Embedder-Policy;
 | 
				
			||||||
add_header Cross-Origin-Embedder-Policy "require-corp" always;
 | 
					add_header Cross-Origin-Embedder-Policy "require-corp" always;
 | 
				
			||||||
 | 
					 | 
				
			||||||
# Access-Control-Max-Age
 | 
					 | 
				
			||||||
proxy_hide_header Access-Control-Max-Age;
 | 
					 | 
				
			||||||
add_header Access-Control-Max-Age "600";
 | 
					 | 
				
			||||||
@@ -13,6 +13,10 @@ add_header X-Content-Type-Options "nosniff" always;
 | 
				
			|||||||
proxy_hide_header X-Permitted-Cross-Domain-Policies;
 | 
					proxy_hide_header X-Permitted-Cross-Domain-Policies;
 | 
				
			||||||
add_header X-Permitted-Cross-Domain-Policies "none" always;
 | 
					add_header X-Permitted-Cross-Domain-Policies "none" always;
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					# Access-Control-Max-Age
 | 
				
			||||||
 | 
					proxy_hide_header Access-Control-Max-Age;
 | 
				
			||||||
 | 
					add_header Access-Control-Max-Age "600";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# Obsolete and replaced by Content-Security-Policy frame-ancestors
 | 
					# Obsolete and replaced by Content-Security-Policy frame-ancestors
 | 
				
			||||||
# Setting the less restrictive SAMEORIGIN here, as frame-ancestors 'none' will overwrite it anyways
 | 
					# Setting the less restrictive SAMEORIGIN here, as frame-ancestors 'none' will overwrite it anyways
 | 
				
			||||||
proxy_hide_header X-Frame-Options;
 | 
					proxy_hide_header X-Frame-Options;
 | 
				
			||||||
 
 | 
				
			|||||||
		Reference in New Issue
	
	Block a user