diff --git a/etc/nginx/snippets/cross-origin-security.conf b/etc/nginx/snippets/cross-origin-security.conf index e8f1b63..0b2458b 100644 --- a/etc/nginx/snippets/cross-origin-security.conf +++ b/etc/nginx/snippets/cross-origin-security.conf @@ -2,10 +2,10 @@ # Meant to be used globally, but some apps may need a manual overwrite, so this is split out from security.conf proxy_hide_header Cross-Origin-Resource-Policy; -add_header Cross-Origin-Resource-Policy cross-origin always; +add_header Cross-Origin-Resource-Policy same-origin always; proxy_hide_header Cross-Origin-Opener-Policy; add_header Cross-Origin-Opener-Policy same-origin always; -proxy_hide_header Cross-Origin-Opener-Policy; -Cross-Origin-Embedder-Policy require-corp always; \ No newline at end of file +proxy_hide_header Cross-Origin-Embedder-Policy; +add_header Cross-Origin-Embedder-Policy require-corp always; \ No newline at end of file