Move Access-Control-Max-Age to security.conf

This commit is contained in:
Tommy 2025-01-03 09:31:47 -07:00 committed by GitHub
parent 8293f6f1c3
commit 023e2cdad3
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
3 changed files with 5 additions and 7 deletions

View File

@ -19,8 +19,6 @@ server {
add_header Cross-Origin-Resource-Policy "same-origin" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
proxy_hide_header Access-Control-Max-Age;
add_header Access-Control-Max-Age "600";
location / {
proxy_pass http://nextcloud:8080;

View File

@ -10,8 +10,4 @@ add_header Cross-Origin-Opener-Policy "same-origin" always;
# Change COEP to "credentialless" when supported by Safari
# https://developer.mozilla.org/en-US/docs/Web/API/Window/credentialless
proxy_hide_header Cross-Origin-Embedder-Policy;
add_header Cross-Origin-Embedder-Policy "require-corp" always;
# Access-Control-Max-Age
proxy_hide_header Access-Control-Max-Age;
add_header Access-Control-Max-Age "600";
add_header Cross-Origin-Embedder-Policy "require-corp" always;

View File

@ -13,6 +13,10 @@ add_header X-Content-Type-Options "nosniff" always;
proxy_hide_header X-Permitted-Cross-Domain-Policies;
add_header X-Permitted-Cross-Domain-Policies "none" always;
# Access-Control-Max-Age
proxy_hide_header Access-Control-Max-Age;
add_header Access-Control-Max-Age "600";
# Obsolete and replaced by Content-Security-Policy frame-ancestors
# Setting the less restrictive SAMEORIGIN here, as frame-ancestors 'none' will overwrite it anyways
proxy_hide_header X-Frame-Options;