# The security headers REPO_POLICIES.md requires on every response. # nginx.conf includes this file, which Dockerfile copies to # /etc/nginx/security-headers.conf. always sends each header on error # responses too. add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; # Scripts and styles load only from the page's own origin. Inline ones # are blocked, style attributes in markup included, so style elements # through classes or element.style. data: images are for the favicon # in index.html. connect-src is * because the browser checks each probe in # src/main.js against it, and also every redirect the probe follows, # and several of those hosts redirect to others; a list of hosts here # would block those probes. It also covers the reports the page sends # to its own origin. add_header Content-Security-Policy "default-src 'self'; connect-src *; img-src 'self' data:; object-src 'none'; base-uri 'none'; form-action 'none'; frame-ancestors 'none'" always; add_header X-Frame-Options DENY always; add_header X-Content-Type-Options nosniff always; # The probed hosts are not told where the page is served from. add_header Referrer-Policy no-referrer always; add_header Permissions-Policy "accelerometer=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), usb=()" always;