Skip to content

Update CSP & Security header handling #39

@chr33s

Description

@chr33s
  • Content-Security-Policy: ... upgrade-insecure-requests
  • Cross-Origin-Embedder-Policy:
  • Cross-Origin-Opener-Policy: same-origin-allow-popups
  • Cross-Origin-Resource-Policy: same-origin
  • Origin-Agent-Cluster: ?1
  • Referrer-Policy: no-referrer
  • Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
  • X-Content-Type-Options: nosniff
  • X-Permitted-Cross-Domain-Policies: none

Metadata

Metadata

Assignees

No one assigned

    Labels

    featureNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions