.htaccess.skeleton 848 B

12345678910111213141516171819
  1. # Production only
  2. <IfModule mod_headers.c>
  3. Header set Access-Control-Allow-Origin "*"
  4. Header set Cross-Origin-Embedder-Policy "unsafe-none"
  5. Header set Cross-Origin-Opener-Policy "same-origin"
  6. Header set Cross-Origin-Resource-Policy "cross-origin"
  7. Header set Origin-Agent-Cluster "?1"
  8. Header set Permissions-Policy "camera=(), display-capture=(), fullscreen=(), geolocation=(), microphone=()"
  9. Header set Referrer-Policy "no-referrer"
  10. #Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload;"
  11. Header set X-Content-Type-Options "nosniff"
  12. Header set X-DNS-Prefetch-Control "off"
  13. Header set X-Download-Options "noopen"
  14. Header set X-Frame-Options "SAMEORIGIN"
  15. Header set X-Permitted-Cross-Domain-Policies "none"
  16. Header set X-XSS-Protection "1; mode=block"
  17. </IfModule>