Security headers

The app sets them on every response, so they hold behind any proxy:

Header Value
Strict-Transport-Security max-age=31536000; includeSubDomains; preload, except on the onion listener
Content-Security-Policy default-src 'self'; scripts and styles only from self or with a per-response nonce, no 'unsafe-inline'
X-Content-Type-Options nosniff
X-Frame-Options DENY
Referrer-Policy no-referrer
Permissions-Policy camera=(), microphone=(), geolocation=(), payment=()

Edit this page on GitHub