Split out cross origin security headers
This commit is contained in:
		@@ -16,6 +16,7 @@ server {
 | 
			
		||||
    include snippets/universal_paths.conf;
 | 
			
		||||
    include snippets/hsts.conf;
 | 
			
		||||
    include snippets/security.conf;
 | 
			
		||||
    include snippets/cross-origin-security.conf;
 | 
			
		||||
    include snippets/quic.conf;
 | 
			
		||||
    include snippets/proxy.conf;
 | 
			
		||||
    proxy_hide_header Content-Security-Policy;
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										11
									
								
								etc/nginx/snippets/cross-origin-security.conf
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										11
									
								
								etc/nginx/snippets/cross-origin-security.conf
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,11 @@
 | 
			
		||||
# CORP, COOP, and COEP headers
 | 
			
		||||
# Meant to be used globally, but some apps may need a manual overwrite, so this is split out from security.conf
 | 
			
		||||
 | 
			
		||||
proxy_hide_header Cross-Origin-Resource-Policy;
 | 
			
		||||
add_header Cross-Origin-Resource-Policy cross-origin always;
 | 
			
		||||
 | 
			
		||||
proxy_hide_header Cross-Origin-Opener-Policy;
 | 
			
		||||
add_header Cross-Origin-Opener-Policy same-origin always;
 | 
			
		||||
 | 
			
		||||
proxy_hide_header Cross-Origin-Opener-Policy;
 | 
			
		||||
Cross-Origin-Embedder-Policy require-corp always;
 | 
			
		||||
@@ -13,12 +13,6 @@ add_header X-Content-Type-Options "nosniff" always;
 | 
			
		||||
proxy_hide_header X-Frame-Options;
 | 
			
		||||
add_header X-Frame-Options "SAMEORIGIN" always;
 | 
			
		||||
 | 
			
		||||
proxy_hide_header Cross-Origin-Resource-Policy;
 | 
			
		||||
add_header Cross-Origin-Resource-Policy cross-origin always;
 | 
			
		||||
 | 
			
		||||
proxy_hide_header Cross-Origin-Opener-Policy;
 | 
			
		||||
add_header Cross-Origin-Opener-Policy same-origin always;
 | 
			
		||||
 | 
			
		||||
# Obsolete and replaced by Content-Security-Policy
 | 
			
		||||
# Only here to pass Hardenize checks
 | 
			
		||||
proxy_hide_header X-XSS-Protection;
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user