Pagure: proper X-Frame-Options header in staging

This commit is contained in:
Julen Landa Alustiza 2019-07-18 23:13:07 +02:00 committed by Pierre-Yves Chibon
parent 10a6ffa7e1
commit 6e9c664a18
1 changed files with 4 additions and 2 deletions

View File

@ -1,7 +1,9 @@
Header always set X-Frame-Options "ALLOW-FROM https://pagure.io/"
Header always set X-Xss-Protection "1; mode=block"
Header always set X-Content-Type-Options "nosniff"
Header always set Referrer-Policy "same-origin"
{% if env != 'pagure-staging' %}
{% if env == 'pagure-staging' %}
Header always set X-Frame-Options "ALLOW-FROM https://stg.pagure.io/"
{% else %}
Header always set X-Frame-Options "ALLOW-FROM https://pagure.io/"
Header always set Content-Security-Policy "default-src 'self' https:; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://apps.fedoraproject.org; style-src 'self' 'unsafe-inline' https://apps.fedoraproject.org"
{% endif %}