diff --git a/conf/nginx.conf b/conf/nginx.conf index 5096c28..6df184f 100644 --- a/conf/nginx.conf +++ b/conf/nginx.conf @@ -13,16 +13,18 @@ location /front/ { more_set_headers Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self' data:; object-src 'none'; media-src 'self' data:"; more_set_headers Referrer-Policy "strict-origin-when-cross-origin"; more_set_headers X-Frame-Options "SAMEORIGIN"; + more_set_headers Service-Worker-Allowed "/"; + } location /front/embed.html { - add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self' data:; object-src 'none'; media-src 'self' data:"; - add_header Referrer-Policy "strict-origin-when-cross-origin"; - add_header X-Frame-Options "ALLOW"; + more_set_headers Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self' data:; object-src 'none'; media-src 'self' data:"; + more_set_headers Referrer-Policy "strict-origin-when-cross-origin"; + more_set_headers X-Frame-Options "ALLOW"; alias __FINALPATH__/code/front/dist/embed.html; expires 30d; - add_header Pragma public; - add_header Cache-Control "public, must-revalidate, proxy-revalidate"; + more_set_headers Pragma public; + more_set_headers Cache-Control "public, must-revalidate, proxy-revalidate"; }