We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
default-src 'none'
1 parent 2a1d16a commit 23b37d0Copy full SHA for 23b37d0
README.md
@@ -77,7 +77,7 @@ SecureHeaders::Configuration.default do |config|
77
preserve_schemes: true, # default: false. Schemes are removed from host sources to save bytes and discourage mixed content.
78
79
# directive values: these values will directly translate into source directives
80
- default_src: %w(https: 'self'),
+ default_src: %w('none'),
81
base_uri: %w('self'),
82
block_all_mixed_content: true, # see http://www.w3.org/TR/mixed-content/
83
child_src: %w('self'), # if child-src isn't supported, the value for frame-src will be set.
0 commit comments