disable header preventing opening links to self, fixes #959

This commit is contained in:
El RIDO 2022-07-31 08:49:36 +02:00
parent 1d74c1ae56
commit d6cead99eb
No known key found for this signature in database
GPG key ID: 0F5C940A6BD81F92

View file

@ -11,7 +11,10 @@ server {
# https://developers.cloudflare.com/cache/about/cache-control#other
add_header Cache-Control "public, max-age=3600, must-revalidate, no-transform";
add_header Cross-Origin-Embedder-Policy require-corp;
add_header Cross-Origin-Opener-Policy same-origin;
# disabled, because it prevents links from a paste to the same site to
# be opened. Didn't work with `same-origin-allow-popups` either.
# See issue #959 for details.
#add_header Cross-Origin-Opener-Policy same-origin;
add_header Cross-Origin-Resource-Policy same-origin;
add_header Referrer-Policy no-referrer;
add_header X-Content-Type-Options nosniff;