File tree Expand file tree Collapse file tree 5 files changed +5
-5
lines changed
Expand file tree Collapse file tree 5 files changed +5
-5
lines changed Original file line number Diff line number Diff line change 55 Header set X-XSS-Protection "1 ; mode=block"
66 Header set X-Content-Type-Options "nosniff"
77 Header set Strict-Transport-Security "max-age=31536000 ; includeSubDomains"
8- Header set Referrer-Policy "no-referrer -when-downgrade "
8+ Header set Referrer-Policy "strict-origin -when-cross-origin "
99 # Put your domain here (or your wildcard *, if you experience any problems)
1010 Header set Access-Control-Allow -Origin "https://YOURDOMAIN.com/"
1111 # Adjust to your needs. GET should be enough for simple landingpages. Sometimes, you might need 'GET, POST'.
Original file line number Diff line number Diff line change 4747
4848// Base URL of your microsite.
4949$ the_page_url = 'https://YOURDOMAIN.com/ ' ;
50- // $the_page_url = '/'; (use this for localhost dev/tests via Docker)
50+ // $the_page_url = '/'; // (use this for localhost dev/tests via Docker)
5151
5252// PWA settings.
5353$ the_webapp_name = 'Put the name for the webapp here ' ; // Mind manifest.json too.
Original file line number Diff line number Diff line change 106106 add_header X-XSS-Protection '1; mode=block' ;
107107 add_header X-Content-Type-Options nosniff;
108108 add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload' ;
109- add_header Referrer-Policy no-referrer -when-downgrade ;
109+ add_header Referrer-Policy strict-origin -when-cross-origin ;
110110 # Uses your domain from the server_name above here (or your wildcard *, if you experience any problems)
111111 add_header Access-Control-Allow-Origin 'https://' $server_name ;
112112 # Adjust to your needs. GET should be enough for simple landingpages. Sometimes, you might need 'GET, POST'.
Original file line number Diff line number Diff line change 3636 }
3737 ?>
3838
39- <!-- Preload fonts (optional, only .woff2 recommended) -->
39+ <!-- Preload fonts (optional, only .woff2 and only the ones you use above the fold recommended) -->
4040 <link rel="preload" href="./assets/fonts/open-sans-v17-latin-regular.woff2" as="font" type="font/woff2" crossorigin>
4141 <link rel="preload" href="./assets/fonts/open-sans-v17-latin-600.woff2" as="font" type="font/woff2" crossorigin>
4242 <link rel="preload" href="./assets/fonts/open-sans-v17-latin-800.woff2" as="font" type="font/woff2" crossorigin>
Original file line number Diff line number Diff line change 66header ("X-XSS-Protection: 1; mode=block " );
77header ("X-Content-Type-Options: nosniff " );
88header ("Strict-Transport-Security: max-age=31536000; includeSubDomains " );
9- header ("Referrer-Policy: no-referrer -when-downgrade " );
9+ header ("Referrer-Policy: strict-origin -when-cross-origin " );
1010header ("Access-Control-Allow-Origin: " . $ the_page_url );
1111// Adjust to your needs. GET should be enough for simple landingpages. Sometimes, you might need 'GET, POST'.
1212header ("Access-Control-Allow-Methods: GET " );
You can’t perform that action at this time.
0 commit comments