mirror of
				https://github.com/linuxserver/docker-swag.git
				synced 2025-10-30 20:47:43 +09:00 
			
		
		
		
	Set frame-ancestors in Content-Security-Policy
https://infosec.mozilla.org/guidelines/web_security#x-frame-options
This commit is contained in:
		| @@ -40,7 +40,7 @@ ssl_early_data on; | ||||
|  | ||||
| # Optional additional headers | ||||
| #add_header Cache-Control "no-transform" always; | ||||
| #add_header Content-Security-Policy "upgrade-insecure-requests"; | ||||
| #add_header Content-Security-Policy "upgrade-insecure-requests; frame-ancestors 'self'"; | ||||
| #add_header Referrer-Policy "same-origin" always; | ||||
| #add_header X-Content-Type-Options "nosniff" always; | ||||
| #add_header X-Frame-Options "SAMEORIGIN" always; | ||||
|   | ||||
		Reference in New Issue
	
	Block a user