From 3a88e45cbc7f9a05eabef929f8d68c6935156fe2 Mon Sep 17 00:00:00 2001 From: staticsafe Date: Tue, 7 Sep 2021 17:24:04 -0400 Subject: [PATCH] remove add_header --- ubuntu/elaine.asininetech.net.yml | 4 ---- 1 file changed, 4 deletions(-) diff --git a/ubuntu/elaine.asininetech.net.yml b/ubuntu/elaine.asininetech.net.yml index 410d450..fec25aa 100644 --- a/ubuntu/elaine.asininetech.net.yml +++ b/ubuntu/elaine.asininetech.net.yml @@ -24,10 +24,6 @@ - ssl_stapling on - resolver [::1] valid=300s - add_header Strict-Transport-Security max-age=31536000 - - add_header Content-Security-Policy "default-src 'none'; script-src 'self' 'unsafe-inline'; img-src 'self'; style-src 'self' 'unsafe-inline'; font-src 'self'; object-src 'none'; media-src 'self' blob:; worker-src 'self' blob:; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; connect-src 'self' https://*.twimg.com; manifest-src 'self'"; - - add_header X-Content-Type-Options nosniff; - - add_header X-Frame-Options DENY; - - add_header X-XSS-Protection "1; mode=block" - location / { proxy_pass http://127.0.0.1:8080; }