From 7784fd23e2b9a67f4bbd4c606caea08b24fc64fd Mon Sep 17 00:00:00 2001 From: Scott Kennedy Date: Tue, 28 Sep 2021 23:32:54 +0100 Subject: [PATCH] Removed security headers --- netlify.toml | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/netlify.toml b/netlify.toml index c149f3f..d932616 100644 --- a/netlify.toml +++ b/netlify.toml @@ -19,12 +19,12 @@ [headers.values] Access-Control-Allow-Origin = "*" Access-Control-Allow-Headers = "Content-Type" - X-XSS-Protection = "1; mode=block" - Referrer-Policy = "no-referrer" - X-Content-Type-Options = "nosniff" - Strict-Transport-Security = "max-age=15780000; includeSubDomains; preload" - Feature-Policy = "geolocation 'none'; midi 'none'; sync-xhr 'none'; microphone 'none'; camera 'none'; magnetometer 'none'; gyroscope 'none'; speaker 'none'; fullscreen 'none'; payment 'none'" - Content-Security-Policy = "default-src * 'unsafe-inline' 'unsafe-eval'; script-src * 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src *; style-src * 'unsafe-inline'" + # X-XSS-Protection = "1; mode=block" + # Referrer-Policy = "no-referrer" + # X-Content-Type-Options = "nosniff" + # Strict-Transport-Security = "max-age=15780000; includeSubDomains; preload" + # Feature-Policy = "geolocation 'none'; midi 'none'; sync-xhr 'none'; microphone 'none'; camera 'none'; magnetometer 'none'; gyroscope 'none'; speaker 'none'; fullscreen 'none'; payment 'none'" + # Content-Security-Policy = "default-src * 'unsafe-inline' 'unsafe-eval'; script-src * 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src *; style-src * 'unsafe-inline'" [[redirects]]