Skip to content

Commit 70168bb

Browse files
committed
Cross-Origin security improvements
1 parent 318a662 commit 70168bb

File tree

2 files changed

+10
-0
lines changed

2 files changed

+10
-0
lines changed

Caddyfile

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,9 @@
1313
Content-Security-Policy "default-src 'none'; base-uri 'none'; object-src 'none'; frame-ancestors 'none'; frame-src 'none'; form-action 'self'; manifest-src 'self'; worker-src 'self'; connect-src 'self'; img-src 'self' data: blob:; font-src 'self' data:; style-src 'self'; script-src 'self' 'wasm-unsafe-eval' 'unsafe-eval'; media-src 'self' blob:; upgrade-insecure-requests"
1414
Referrer-Policy "no-referrer"
1515
Permissions-Policy "autoplay=(self), fullscreen=(self), picture-in-picture=(), geolocation=(), microphone=(), camera=(), display-capture=(), screen-wake-lock=(), usb=(), serial=(), hid=(), midi=(), payment=(), accelerometer=(), gyroscope=(), magnetometer=(), clipboard-read=(), clipboard-write=(), idle-detection=(), encrypted-media=(), storage-access=(), attribution-reporting=(), browsing-topics=(), run-ad-auction=(), join-ad-interest-group=(), publickey-credentials-get=(), xr-spatial-tracking=(), gamepad=(), sync-xhr=(), local-fonts=(), otp-credentials=(), window-management=()"
16+
Cross-Origin-Embedder-Policy "require-corp"
1617
Cross-Origin-Resource-Policy "same-origin"
18+
Cross-Origin-Opener-Policy "same-origin"
1719
Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
1820
}
1921

vercel.json

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,14 @@
2626
"key": "Cross-Origin-Resource-Policy",
2727
"value": "same-origin"
2828
},
29+
{
30+
"key": "Cross-Origin-Opener-Policy",
31+
"value": "same-origin"
32+
},
33+
{
34+
"key": "Cross-Origin-Embedder-Policy",
35+
"value": "require-corp"
36+
},
2937
{
3038
"key": "Strict-Transport-Security",
3139
"value": "max-age=63072000; includeSubDomains; preload"

0 commit comments

Comments
 (0)