diff --git a/config/http/default.nix b/config/http/default.nix index 1753981..ffd1e1e 100644 --- a/config/http/default.nix +++ b/config/http/default.nix @@ -16,6 +16,7 @@ in { recommendedBrotliSettings = true; appendHttpConfig = '' + add_header_inherit merge; add_header Content-Security-Policy "script-src 'self'; object-src 'none'; base-uri 'none';" always; add_header 'Referrer-Policy' 'origin-when-cross-origin'; add_header X-Frame-Options DENY;