From dba38a0e555fa18171052a3ac5b66ee56437a195 Mon Sep 17 00:00:00 2001 From: Dominik Hebeler <dominik@suma-ev.de> Date: Fri, 5 Apr 2024 10:20:36 +0200 Subject: [PATCH] allow underscores in header --- build/nginx/configuration/nginx.conf | 2 ++ 1 file changed, 2 insertions(+) diff --git a/build/nginx/configuration/nginx.conf b/build/nginx/configuration/nginx.conf index 4f69430aa..4b60457c4 100644 --- a/build/nginx/configuration/nginx.conf +++ b/build/nginx/configuration/nginx.conf @@ -28,6 +28,8 @@ http { '' "default-src 'self'; script-src 'self'; script-src-elem 'self'; script-src-attr 'self'; style-src 'self'; style-src-elem 'self'; style-src-attr 'self'; img-src 'self' data:; font-src 'self'; connect-src 'self'; frame-src 'self'; frame-ancestors 'self' https://scripts.zdv.uni-mainz.de; form-action 'self' metager.org metager.de"; } + underscores_in_headers "on"; + add_header "X-Frame-Options" "sameorigin"; add_header "X-Content-Type-Options" "nosniff"; add_header "ReferrerPolicy" "origin"; -- GitLab