12 lines
938 B
Plaintext
12 lines
938 B
Plaintext
# Headers for the bundled Element Call page (/public/element-call/).
|
|||
|
|
# Same as cinny-security-headers.conf minus the Content-Security-Policy: the app
|
||
|
|
# embeds this page in an iframe, and the app CSP's frame-ancestors 'none' (plus a
|
||
|
|
# connect-src that doesn't list the call backends) blocked it. X-Frame-Options
|
||
|
|
# SAMEORIGIN still limits framing to chat.lotusguild.org itself.
|
||
|
|
add_header X-Frame-Options SAMEORIGIN always;
|
||
|
|
add_header X-Content-Type-Options nosniff always;
|
||
|
|
add_header X-XSS-Protection "1; mode=block" always;
|
||
|
|
add_header Referrer-Policy strict-origin-when-cross-origin always;
|
||
|
|
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;
|
||
|
|
add_header Permissions-Policy "accelerometer=(), autoplay=(self), camera=(self), display-capture=(self), encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(), magnetometer=(), microphone=(self), midi=(), payment=(), usb=()" always;
|