web-maintenance/netlify.toml
Dominic Reich d07771c46d
update CSP
2019-03-16 20:25:32 +01:00

24 lines
861 B
TOML

[build]
command = ""
publish = "dist"
[[headers]]
for = "/*"
[headers.values]
Strict-Transport-Security = "max-age=31536000; includeSubDomains; preload"
Cache-Control = "public, max-age=31536000"
Referrer-Policy = "strict-origin-when-cross-origin"
Content-Security-Policy = "default-src 'unsafe-inline' https:"
X-Content-Type-Options = "nosniff"
X-Frame-Options = "DENY"
X-XSS-Protection = "1; mode=block"
# Referrer-Policy = "no-referrer"
Access-Control-Allow-Origin = "*"
Vary = "Accept-Encoding"
Access-Control-Allow-Credentials = "true"
Feature-Policy = "geolocation 'self' https://dominicreich.com; autoplay 'none'; lazyload 'self' https://dominicreich.com; sync-xhr 'self' https://dominicreich.com"
[[headers]]
for = "/assets/*"
[headers.values]
Cache-Control = "public, max-age=31536000"