diff --git a/h5bp/security/permissions-policy.conf b/h5bp/security/permissions-policy.conf index 2df5a533..038b5d2b 100644 --- a/h5bp/security/permissions-policy.conf +++ b/h5bp/security/permissions-policy.conf @@ -21,5 +21,27 @@ # https://scotthelme.co.uk/a-new-security-header-feature-policy/ - Header always set Permissions-Policy "accelerometer=(),autoplay=(),browsing-topics=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=()" "expr=%{CONTENT_TYPE} =~ m#text\/(html|javascript)|application\/pdf|xml#i" + Header always set Permissions-Policy "\ + accelerometer=(),\ + autoplay=(),\ + browsing-topics=(),\ + camera=(),\ + display-capture=(),\ + document-domain=(),\ + encrypted-media=(),\ + fullscreen=(),\ + geolocation=(),\ + gyroscope=(),\ + magnetometer=(),\ + microphone=(),\ + midi=(),\ + payment=(),\ + picture-in-picture=(),\ + publickey-credentials-get=(),\ + screen-wake-lock=(),\ + sync-xhr=(self),\ + usb=(),\ + web-share=(),\ + xr-spatial-tracking=()\ + " "expr=%{CONTENT_TYPE} =~ m#text\/(html|javascript)|application\/pdf|xml#i"