We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent a58e188 commit a6cd315Copy full SHA for a6cd315
1 file changed
root/defaults/nginx/ssl.conf.sample
@@ -21,8 +21,8 @@ ssl_session_cache shared:MozSSL:10m; # about 40000 sessions
21
22
### Mozilla Practical security implementation
23
# https://developer.mozilla.org/en-US/docs/Web/Security
24
-#add_header Access-Control-Allow-Origin "*" always;
25
-#add_header Content-Security-Policy "upgrade-insecure-requests; base-uri 'self'; form-action 'self'; frame-ancestors 'self'" always;
+#add_header Access-Control-Allow-Origin $http_origin always;
+#add_header Content-Security-Policy "upgrade-insecure-requests; base-uri 'self'; form-action 'self'; frame-ancestors 'self';" always;
26
#add_header Cross-Origin-Resource-Policy "same-origin" always;
27
#add_header Referrer-Policy "same-origin" always;
28
#add_header X-Content-Type-Options "nosniff" always;
0 commit comments