server { listen ipv4_1:443 quic; listen ipv4_1:443 ssl; listen [ipv6_1]:443 quic; listen [ipv6_1]:443 ssl; server_name miniflux.yourdomain.tld; ssl_certificate /etc/letsencrypt/live/miniflux.yourdomain.tld/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/miniflux.yourdomain.tld/privkey.pem; ssl_trusted_certificate /etc/letsencrypt/live/miniflux.yourdomain.tld/chain.pem; include snippets/hsts.conf; include snippets/security.conf; include snippets/cross-origin-security.conf; include snippets/quic.conf; include snippets/proxy.conf; include snippets/robots.conf; include snippets/universal_paths.conf; proxy_hide_header Content-Security-Policy; add_header Content-Security-Policy "default-src 'none'; connect-src 'self'; frame-src *; img-src *; manifest-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; base-uri 'none'; block-all-mixed-content; form-action 'self'; frame-ancestors 'self'; upgrade-insecure-requests"; location / { proxy_pass http://miniflux:8080; } }