sitespeed.io/docs/_headers

27 lines
1.1 KiB
Plaintext

/*
X-Content-Type-Options: nosniff
x-frame-options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Referrer-Policy: no-referrer
Permissions-Policy: interest-cohort=()
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'
Cache-Control: public, max-age=0, must-revalidate, no-transform
Strict-Transport-Security: max-age=31536000; includeSubDomains
/search/*
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline';
/video/*
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; child-src https://www.youtube.com; img-src 'self' https://i.ytimg.com;
/testcases/*
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self';
/img/*
Cache-Control: public, max-age=3600000
/js/*
Cache-Control: public, max-age=3600000
/css/*
Cache-Control: public, max-age=3600000
/feed/*
Access-Control-Allow-Origin: *