File tree Expand file tree Collapse file tree 5 files changed +5
-5
lines changed Expand file tree Collapse file tree 5 files changed +5
-5
lines changed Original file line number Diff line number Diff line change 5
5
Header set X-XSS-Protection "1 ; mode=block"
6
6
Header set X-Content-Type-Options "nosniff"
7
7
Header set Strict-Transport-Security "max-age=31536000 ; includeSubDomains"
8
- Header set Referrer-Policy "no-referrer -when-downgrade "
8
+ Header set Referrer-Policy "strict-origin -when-cross-origin "
9
9
# Put your domain here (or your wildcard *, if you experience any problems)
10
10
Header set Access-Control-Allow -Origin "https://YOURDOMAIN.com/"
11
11
# Adjust to your needs. GET should be enough for simple landingpages. Sometimes, you might need 'GET, POST'.
Original file line number Diff line number Diff line change 47
47
48
48
// Base URL of your microsite.
49
49
$ the_page_url = 'https://YOURDOMAIN.com/ ' ;
50
- // $the_page_url = '/'; (use this for localhost dev/tests via Docker)
50
+ // $the_page_url = '/'; // (use this for localhost dev/tests via Docker)
51
51
52
52
// PWA settings.
53
53
$ the_webapp_name = 'Put the name for the webapp here ' ; // Mind manifest.json too.
Original file line number Diff line number Diff line change 106
106
add_header X-XSS-Protection '1; mode=block' ;
107
107
add_header X-Content-Type-Options nosniff;
108
108
add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload' ;
109
- add_header Referrer-Policy no-referrer -when-downgrade ;
109
+ add_header Referrer-Policy strict-origin -when-cross-origin ;
110
110
# Uses your domain from the server_name above here (or your wildcard *, if you experience any problems)
111
111
add_header Access-Control-Allow-Origin 'https://' $server_name ;
112
112
# Adjust to your needs. GET should be enough for simple landingpages. Sometimes, you might need 'GET, POST'.
Original file line number Diff line number Diff line change 36
36
}
37
37
?>
38
38
39
- <!-- Preload fonts (optional, only .woff2 recommended) -->
39
+ <!-- Preload fonts (optional, only .woff2 and only the ones you use above the fold recommended) -->
40
40
<link rel="preload" href="./assets/fonts/open-sans-v17-latin-regular.woff2" as="font" type="font/woff2" crossorigin>
41
41
<link rel="preload" href="./assets/fonts/open-sans-v17-latin-600.woff2" as="font" type="font/woff2" crossorigin>
42
42
<link rel="preload" href="./assets/fonts/open-sans-v17-latin-800.woff2" as="font" type="font/woff2" crossorigin>
Original file line number Diff line number Diff line change 6
6
header ("X-XSS-Protection: 1; mode=block " );
7
7
header ("X-Content-Type-Options: nosniff " );
8
8
header ("Strict-Transport-Security: max-age=31536000; includeSubDomains " );
9
- header ("Referrer-Policy: no-referrer -when-downgrade " );
9
+ header ("Referrer-Policy: strict-origin -when-cross-origin " );
10
10
header ("Access-Control-Allow-Origin: " . $ the_page_url );
11
11
// Adjust to your needs. GET should be enough for simple landingpages. Sometimes, you might need 'GET, POST'.
12
12
header ("Access-Control-Allow-Methods: GET " );
You can’t perform that action at this time.
0 commit comments