| @@ -177,7 +177,7 @@ element.DOMAIN.tld { | |||||
| # # Prevent some browsers from MIME-sniffing a response away from the declared Content-Type | # # Prevent some browsers from MIME-sniffing a response away from the declared Content-Type | ||||
| # X-Content-Type-Options "nosniff" | # X-Content-Type-Options "nosniff" | ||||
| # # Only allow same base domain to render this website in a frame; Can be removed if the client (Element for example) is hosted on another domain (clickjacking protection) | # # Only allow same base domain to render this website in a frame; Can be removed if the client (Element for example) is hosted on another domain (clickjacking protection) | ||||
| # # Content-Security-Policy frame-ancestors https://*.DOMAIN.tld | |||||
| # Content-Security-Policy frame-ancestors https://*.DOMAIN.tld | |||||
| # # X-Robots-Tag | # # X-Robots-Tag | ||||
| # X-Robots-Tag "noindex, noarchive, nofollow" | # X-Robots-Tag "noindex, noarchive, nofollow" | ||||
| # } | # } | ||||
| @@ -214,7 +214,7 @@ element.DOMAIN.tld { | |||||
| # X-Content-Type-Options "nosniff" | # X-Content-Type-Options "nosniff" | ||||
| # # Only allow same base domain to render this website in a frame; Can be removed if the client (Element for example) is hosted on another domain | # # Only allow same base domain to render this website in a frame; Can be removed if the client (Element for example) is hosted on another domain | ||||
| # # Content-Security-Policy frame-ancestors https://*.DOMAIN.tld | |||||
| # Content-Security-Policy frame-ancestors https://*.DOMAIN.tld | |||||
| # | # | ||||
| # # Disable some features | # # Disable some features | ||||
| # Feature-Policy "accelerometer 'none';ambient-light-sensor 'none'; autoplay 'none';camera 'none';encrypted-media 'none';focus-without-user-activation 'none'; geolocation 'none';gyroscope #'none';magnetometer 'none';microphone 'none';midi 'none';payment 'none';picture-in-picture 'none'; speaker 'none';sync-xhr 'none';usb 'none';vr 'none'" | # Feature-Policy "accelerometer 'none';ambient-light-sensor 'none'; autoplay 'none';camera 'none';encrypted-media 'none';focus-without-user-activation 'none'; geolocation 'none';gyroscope #'none';magnetometer 'none';microphone 'none';midi 'none';payment 'none';picture-in-picture 'none'; speaker 'none';sync-xhr 'none';usb 'none';vr 'none'" | ||||