change default referrer policy to same-origin

https://forum.cloudron.io/topic/4546/referrer-policy-header-is-overwritten
This commit is contained in:
Girish Ramakrishnan
2021-03-01 09:34:21 -08:00
parent 376e070b72
commit dd58c174a8

View File

@@ -95,7 +95,7 @@ server {
proxy_hide_header X-Content-Type-Options;
add_header X-Permitted-Cross-Domain-Policies "none";
proxy_hide_header X-Permitted-Cross-Domain-Policies;
add_header Referrer-Policy "no-referrer-when-downgrade";
add_header Referrer-Policy "same-origin";
proxy_hide_header Referrer-Policy;
# workaround caching issue after /logout. if max-age is set, browser uses cache and user thinks they have not logged out