add sameorigin header

This commit is contained in:
Sebastian Hugentobler 2019-10-08 14:29:57 +02:00
parent 124ee44164
commit 4bae3cb9fa

View File

@ -16,6 +16,7 @@ server {
add_header X-Download-Options noopen; add_header X-Download-Options noopen;
add_header X-Permitted-Cross-Domain-Policies none; add_header X-Permitted-Cross-Domain-Policies none;
add_header Referrer-Policy no-referrer; add_header Referrer-Policy no-referrer;
add_header X-Frame-Options "SAMEORIGIN" always;
fastcgi_hide_header X-Powered-By; fastcgi_hide_header X-Powered-By;
@ -28,11 +29,11 @@ server {
} }
location = /.well-known/carddav { location = /.well-known/carddav {
return 301 $scheme://$host/remote.php/dav; return 301 $scheme://$host:$server_port/remote.php/dav;
} }
location = /.well-known/caldav { location = /.well-known/caldav {
return 301 $scheme://$host/remote.php/dav; return 301 $scheme://$host:$server_port/remote.php/dav;
} }
client_max_body_size {{getenv "MAX_UPLOAD_SIZE"}}; client_max_body_size {{getenv "MAX_UPLOAD_SIZE"}};