Restrict CORP

This commit is contained in:
Tommy 2024-06-25 15:15:59 -07:00 committed by GitHub
parent 03149c183c
commit 4f1b4b6dcb
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -2,10 +2,10 @@
# Meant to be used globally, but some apps may need a manual overwrite, so this is split out from security.conf
proxy_hide_header Cross-Origin-Resource-Policy;
add_header Cross-Origin-Resource-Policy cross-origin always;
add_header Cross-Origin-Resource-Policy same-origin always;
proxy_hide_header Cross-Origin-Opener-Policy;
add_header Cross-Origin-Opener-Policy same-origin always;
proxy_hide_header Cross-Origin-Opener-Policy;
Cross-Origin-Embedder-Policy require-corp always;
proxy_hide_header Cross-Origin-Embedder-Policy;
add_header Cross-Origin-Embedder-Policy require-corp always;