Commit 5d04c87
Lukas Puehringer
Configure https security headers
The following headers are added:
Content-Security-Policy: allow loading any content from jquery (js),
and google and fontawesome (fonts and style).
X-Frame-Options: Don't allow iframes
X-Content-Type-Options: stop browser from trying to MIME-sniff the
content type and force it to stick with the declared content-type.
Referrer-Policy: Don't include referrer path in when moving from
https to http.
Permissions-Policy: Disallow FloC Web-Tracking (experimental)
See scan result and details about individual headers on:
https://securityheaders.com/?q=https%3A%2F%2Ftheupdateframework.io
Cheers to @adityasaky and his model PR in in-toto/in-toto.io#7
Signed-off-by: Lukas Puehringer <lukas.puehringer@nyu.edu>1 parent dc9b68c commit 5d04c87
1 file changed
+9
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
0 commit comments