add Permissions-Policy #7

Merged
meaz merged 2 commits from Permissions_policy into master 4 weeks ago
meaz commented 4 weeks ago
Owner
Block google Floc https://plausible.io/blog/google-floc
muppeth was assigned by meaz 4 weeks ago
antilopa was assigned by meaz 4 weeks ago
meaz added 1 commit 4 weeks ago
Owner

Great. Thanks @meaz I would however use opt-out scenario instead of opt in. Same as we do with for example xss:

{% if item.permission_policy is defined and item.permission_policy == 'none' %}
{% else %}
  add_header Permissions-Policy "geolocation=(),interest-cohort=()";
{% endif %}

In that way we block that shit by default and dont need to adjust all vhosts everywhere and only enable if we want to allow it.

Great. Thanks @meaz I would however use opt-out scenario instead of opt in. Same as we do with for example xss: ``` {% if item.permission_policy is defined and item.permission_policy == 'none' %} {% else %} add_header Permissions-Policy "geolocation=(),interest-cohort=()"; {% endif %} ``` In that way we block that shit by default and dont need to adjust all vhosts everywhere and only enable if we want to allow it.
meaz added 1 commit 4 weeks ago
Poster
Owner

done

done
muppeth approved these changes 4 weeks ago
antilopa approved these changes 4 weeks ago
meaz merged commit ac73da2014 into master 4 weeks ago

Reviewers

muppeth approved these changes 4 weeks ago
antilopa approved these changes 4 weeks ago
The pull request has been merged as ac73da2014.
Sign in to join this conversation.
No Milestone
No project
3 Participants
Notifications
Due Date

No due date set.

Dependencies

This pull request currently doesn't have any dependencies.

Loading…
There is no content yet.