mirror of https://github.com/zulip/zulip.git
nginx: Add CORS headers to /user_uploads.
Fixes: #12980. Signed-off-by: Anders Kaseorg <anders@zulipchat.com>
This commit is contained in:
parent
73330f3136
commit
263d71bf2b
|
@ -1,5 +1,6 @@
|
||||||
location /serve_uploads {
|
location /serve_uploads {
|
||||||
internal;
|
internal;
|
||||||
|
include /etc/nginx/zulip-include/api_headers;
|
||||||
add_header X-Content-Type-Options nosniff;
|
add_header X-Content-Type-Options nosniff;
|
||||||
add_header Content-Security-Policy "default-src 'none'; style-src 'self' 'unsafe-inline'; img-src 'self'; object-src 'self'; plugin-types application/pdf;";
|
add_header Content-Security-Policy "default-src 'none'; style-src 'self' 'unsafe-inline'; img-src 'self'; object-src 'self'; plugin-types application/pdf;";
|
||||||
include /etc/nginx/zulip-include/uploads.types;
|
include /etc/nginx/zulip-include/uploads.types;
|
||||||
|
|
Loading…
Reference in New Issue