Disable DNS prefetching

This commit is contained in:
Simon Ser 2020-01-20 18:26:22 +01:00
parent a66ef1059b
commit b9a180b154
No known key found for this signature in database
GPG key ID: 0FDE7BE0E88F5E48

View file

@ -305,6 +305,8 @@ func New(e *echo.Echo, options *Options) (*Server, error) {
// `style-src 'unsafe-inline'` is required for e-mails with
// embedded stylesheets
ectx.Response().Header().Set("Content-Security-Policy", "default-src 'self'; style-src 'self' 'unsafe-inline'")
// DNS prefetching has privacy implications
ectx.Response().Header().Set("X-DNS-Prefetch-Control", "off")
return next(ectx)
}
})