Skip to content

Commit e34d051

Browse files
author
ci bot
committed
Merge branch 'aarthy/headers' into 'enterprise'
fix(security): add cors header See merge request dkinternal/observability/dataops-observability!52
2 parents cb3df00 + 410d52b commit e34d051

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

observability_ui/nginx.conf

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -70,6 +70,7 @@ http {
7070
add_header Referrer-Policy strict-origin-when-cross-origin;
7171
add_header Permissions-Policy "attribution-reporting=(self),deferred-fetch=(self),deferred-fetch-minimal=(self),fullscreen=(self),storage-access=(self),web-share=(self),accelerometer=(),autoplay=(),bluetooth=(),camera=(),captured-surface-control=(),compute-pressure=(),cross-origin-isolated=(),display-capture=(),encrypted-media=(),gamepad=(),geolocation=(),gyroscope=(),hid=(),identity-credentials-get=(),idle-detection=(),language-detector=(),microphone=(),local-fonts=(),midi=(),otp-credentials=(),payment=(),picture-in-picture=(),publickey-credentials-create=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),summarizer=(),translator=(),usb=(),window-management=(),xr-spatial-tracking=()";
7272
add_header Cross-Origin-Opener-Policy same-origin;
73+
add_header Cross-Origin-Resource-Policy same-origin;
7374
add_header Cross-Origin-Embedder-Policy require-corp;
7475
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'nonce-${request_id}' https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; img-src 'self' data:; font-src 'self' https://fonts.gstatic.com https://cdn.jsdelivr.net; frame-ancestors 'none'; connect-src 'self' https://fonts.gstatic.com https://cdn.jsdelivr.net ${api_hostname}; ${csp_extra}" always;
7576
}

0 commit comments

Comments
 (0)