51165aea by Jeff Balicki

htaccess

Signed-off-by: Jeff <jeff@gotenzing.com>
1 parent 97833bf7
...@@ -153,6 +153,7 @@ ModPagespeed off ...@@ -153,6 +153,7 @@ ModPagespeed off
153 Header set X-Content-Type-Options "nosniff" 153 Header set X-Content-Type-Options "nosniff"
154 Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" 154 Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
155 # Header set Content-Security-Policy ... 155 # Header set Content-Security-Policy ...
156 Header add Content-Security-Policy "default-src 'self';"
156 Header set Referrer-Policy "same-origin" 157 Header set Referrer-Policy "same-origin"
157 Header set Feature-Policy "geolocation 'self'; vibrate 'none'" 158 Header set Feature-Policy "geolocation 'self'; vibrate 'none'"
158 </IfModule> 159 </IfModule>
......