mirror of
https://github.com/scm-manager/scm-manager.git
synced 2026-01-27 09:49:09 +01:00
Remove content security header upgrade-insecure-requests which breaks http only server configs
This commit is contained in:
@@ -44,7 +44,6 @@ public class SecurityHeadersFilter extends HttpFilter {
|
||||
"form-action 'self'; " +
|
||||
"object-src 'none'; " +
|
||||
"frame-ancestors 'none'; " +
|
||||
"upgrade-insecure-requests; " +
|
||||
"block-all-mixed-content"
|
||||
);
|
||||
response.setHeader("Permissions-Policy",
|
||||
|
||||
Reference in New Issue
Block a user