disable header preventing opening links to self, fixes #959
This commit is contained in:
parent
1d74c1ae56
commit
d6cead99eb
1 changed files with 4 additions and 1 deletions
|
@ -11,7 +11,10 @@ server {
|
|||
# https://developers.cloudflare.com/cache/about/cache-control#other
|
||||
add_header Cache-Control "public, max-age=3600, must-revalidate, no-transform";
|
||||
add_header Cross-Origin-Embedder-Policy require-corp;
|
||||
add_header Cross-Origin-Opener-Policy same-origin;
|
||||
# disabled, because it prevents links from a paste to the same site to
|
||||
# be opened. Didn't work with `same-origin-allow-popups` either.
|
||||
# See issue #959 for details.
|
||||
#add_header Cross-Origin-Opener-Policy same-origin;
|
||||
add_header Cross-Origin-Resource-Policy same-origin;
|
||||
add_header Referrer-Policy no-referrer;
|
||||
add_header X-Content-Type-Options nosniff;
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue