reenable same-origin CSP

This commit is contained in:
ansuz 2017-07-31 15:43:47 +02:00
parent 542d0cd17f
commit eebe473f13

View File

@ -18,7 +18,7 @@ module.exports = {
httpHeaders: { httpHeaders: {
"X-XSS-Protection": "1; mode=block", "X-XSS-Protection": "1; mode=block",
"X-Content-Type-Options": "nosniff", "X-Content-Type-Options": "nosniff",
// 'X-Frame-Options': 'SAMEORIGIN', 'X-Frame-Options': 'SAMEORIGIN',
}, },
contentSecurity: [ contentSecurity: [