diff --git a/webserver.js b/webserver.js index 792f7d9f..92f90b21 100644 --- a/webserver.js +++ b/webserver.js @@ -5302,8 +5302,9 @@ module.exports.CreateWebServer = function (parent, db, args, certificates) { const headers = { 'Referrer-Policy': 'no-referrer', 'X-XSS-Protection': '1; mode=block', - 'X-Content-Type-Options': 'nosniff' - //'Content-Security-Policy': "default-src 'none'; font-src 'self'; script-src 'self' 'unsafe-inline'" + extraScriptSrc + "; connect-src 'self'" + geourl + selfurl + "; img-src 'self'" + geourl + " data:; style-src 'self' 'unsafe-inline'; frame-src 'self' https://*.youtube.com mcrouter:; media-src 'self'; form-action 'self'" + 'X-Content-Type-Options': 'nosniff', + 'Permissions-Policy': 'interest-cohort=()', // Remove Google's FLoC Network + 'Content-Security-Policy': "default-src 'none'; font-src 'self'; script-src 'self' 'unsafe-inline'" + extraScriptSrc + "; connect-src 'self'" + geourl + selfurl + "; img-src 'self'" + geourl + " data:; style-src 'self' 'unsafe-inline'; frame-src 'self' mcrouter:; media-src 'self'; form-action 'self'" }; if ((parent.config.settings.allowframing !== true) && (typeof parent.config.settings.allowframing !== 'string')) { headers['X-Frame-Options'] = 'sameorigin'; } res.set(headers);