diff --git a/element/element.theschricks.com.conf b/element/element.theschricks.com.conf index 11be12f..7a96659 100644 --- a/element/element.theschricks.com.conf +++ b/element/element.theschricks.com.conf @@ -9,6 +9,7 @@ server { location / { try_files $uri $uri/ =404; + proxy_cookie_path / "/; secure; HttpOnly; SameSite=strict"; } client_max_body_size 512m; @@ -28,7 +29,6 @@ server { add_header X-Frame-Options "SAMEORIGIN"; add_header Referrer-Policy "strict-origin"; add_header Permissions-Policy "geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()"; - add_header Set-Cookie "Path=/; HttpOnly; Secure"; # CSP add_header Content-Security-Policy "frame-ancestors 'self'";