Skip to content

Commit c2cda11

Browse files
authored
feat: x-frame security options (prisma#1656)
1 parent f7a751b commit c2cda11

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

netlify.toml

+6
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,12 @@ INDEX_ALGOLIA = "true"
1212
for = "/*"
1313
[headers.values]
1414
Access-Control-Allow-Origin = "https://www.prisma.io"
15+
Strict-Transport-Security = "max-age=63072000; includeSubDomains; preload"
16+
Content-Security-Policy = "default-src data: 'unsafe-inline' 'unsafe-eval' https:; script-src data: 'unsafe-inline' 'unsafe-eval' https: blob:; style-src data: 'unsafe-inline' https:; img-src data: https: blob:; font-src data: https:; connect-src https: wss: blob:; media-src https: blob:; object-src https:; child-src https: data: blob:; form-action https:; block-all-mixed-content"
17+
X-Frame-Options = "DENY"
18+
X-Content-Type-Options = "nosniff"
19+
Referrer-Policy = "no-referrer"
20+
Feature-Policy = "microphone 'none'; geolocation 'none'"
1521

1622
[[redirects]]
1723
from = "/docs/*"

0 commit comments

Comments
 (0)