Files
matrix/cinny/nginx-security-headers-call.conf
T

15 lines
1.1 KiB
Plaintext
Raw Normal View History

# Headers for the Element Call page on its own origin, call.chat.lotusguild.org
# (cinny #43). Installed on LXC 106 as /etc/nginx/snippets/cinny-security-headers-call.conf
# (deploy/lxc106-cinny.sh does NOT copy snippets — install by hand, like the others).
#
# frame-ancestors: only the web app may frame the call page (replaces
# X-Frame-Options SAMEORIGIN, which would block the now cross-origin parent;
# browsers honour frame-ancestors over X-Frame-Options anyway).
# Permissions-Policy: "self" here is the call origin, which is what uses the
# mic/camera/screen; the app's own policy delegates them to this origin.
add_header Content-Security-Policy "frame-ancestors https://chat.lotusguild.org" always;
add_header X-Content-Type-Options nosniff always;
add_header Referrer-Policy strict-origin-when-cross-origin always;
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;
add_header Permissions-Policy "accelerometer=(), autoplay=(self), camera=(self), display-capture=(self), encrypted-media=(self), fullscreen=(self), geolocation=(), gyroscope=(), magnetometer=(), microphone=(self), midi=(), payment=(), usb=()" always;