remove default HTTP CSP, put your CSP in your HTML

This commit is contained in:
Quentin 2023-10-03 16:00:11 +02:00
parent 9e113416ac
commit 56e19ff2e5
Signed by untrusted user: quentin
GPG key ID: E9602264D639FF68

View file

@ -134,7 +134,6 @@ job "garage" {
tags = [
"garage-web",
"tricot * 1",
"tricot-add-header Content-Security-Policy default-src https: 'unsafe-inline'; object-src 'none'",
"tricot-add-header Strict-Transport-Security max-age=63072000; includeSubDomains; preload",
"tricot-add-header X-Frame-Options SAMEORIGIN",
"tricot-add-header X-XSS-Protection 1; mode=block",