...
Bloco de código | ||
---|---|---|
| ||
<httpProtocol>
<customHeaders>
<add name="X-Content-Type-Options" value="nosniff" />
<add name="X-Xss-Protection" value="1; mode=block" />
<add name="X-Frame-Options" value="SAMEORIGIN" />
<add name="Cache-Control" value="no-store" />
<add name="Strict-Transport-Security" value="max-age=31536000; includeSubDomains; preload" />
<add name="Cross-Origin-Embedder-Policy" value="require-corp" />
<add name="Cross-Origin-Resource-Policy" value="same-origin" />
<add name="Cross-Origin-Opener-Policy" value="same-origin" />
<add name="Permissions-Policy" value="camera=(self), microphone=(self), geolocation=(self), fullscreen=(self), storage-access=(self)" />
<add name="Referrer-Policy" value="no-referrer-when-downgrade" />
<add name="Content-Security-Policy" value="default-src 'self';
script-src 'self' https://www.googletagmanager.com;
style-src 'self';
img-src 'self';
font-src 'self';
connect-src 'self';
frame-src 'self';
frame-ancestors 'self';" />
</customHeaders>
</httpProtocol> |
...