nginx.conf/snippets.d/global-resource.conf
Arija A. c4f0aaea5f
Initialise Nginx config
Signed-off-by: Arija A. <ari@ari.lt>
2025-09-25 22:45:48 +03:00

12 lines
1.2 KiB
Text

add_header Access-Control-Allow-Origin "*" always;
add_header Access-Control-Allow-Methods "GET, HEAD, OPTIONS" always;
add_header Cross-Origin-Resource-Policy "cross-origin" always;
add_header Cross-Origin-Embedder-Policy "unsafe-none" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Content-Security-Policy "default-src 'none'; upgrade-insecure-requests" always;
add_header Expires "Thu, 01 Jan 1970 00:00:00 GMT" always;
add_header Cache-Control "no-cache, no-store, must-revalidate" always;
add_header Permissions-Policy "accelerometer=(), autoplay=(), camera=(), cross-origin-isolated=(), display-capture=(), encrypted-media=(), fullscreen=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=(), clipboard-read=(), clipboard-write=(), gamepad=(), hid=(), idle-detection=(), interest-cohort=(), serial=(), unload=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-XSS-Protection "0" always;
add_header Referrer-Policy "no-referrer" always;