Security headers
The app sets them on every response, so they hold behind any proxy:
| Header | Value |
|---|---|
Strict-Transport-Security |
max-age=31536000; includeSubDomains; preload, except on the onion listener |
Content-Security-Policy |
default-src 'self'; scripts and styles only from self or with a per-response nonce, no 'unsafe-inline' |
X-Content-Type-Options |
nosniff |
X-Frame-Options |
DENY |
Referrer-Policy |
no-referrer |
Permissions-Policy |
camera=(), microphone=(), geolocation=(), payment=() |