diff --git a/files/etc/nginx/conf.d/headers.conf b/files/etc/nginx/conf.d/headers.conf index 48b0733..8c611e5 100644 --- a/files/etc/nginx/conf.d/headers.conf +++ b/files/etc/nginx/conf.d/headers.conf @@ -1,4 +1,3 @@ -add_header Referrer-Policy no-referrer; add_header X-Content-Type-Options nosniff; add_header X-XSS-Protection "1; mode=block"; add_header X-Frame-Options "SAMEORIGIN" always; diff --git a/templates/vhosts/partials/header.j2 b/templates/vhosts/partials/header.j2 index 756cdfb..d02c4ef 100644 --- a/templates/vhosts/partials/header.j2 +++ b/templates/vhosts/partials/header.j2 @@ -28,3 +28,6 @@ add_header Content-Security-Policy-Report-Only "{{ item.csp_report }} report-uri {% if item.server is defined %} more_set_headers "Server : {{ item.server }}"; {% endif %} + + +add_header Referrer-Policy {{ item.referer | default('no-referrer') }};