Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 12 additions & 1 deletion .htaccess
Original file line number Diff line number Diff line change
@@ -1,4 +1,15 @@

IndexIgnore *

Options -Indexes

# Basic security headers.
# These defaults are intentionally conservative to avoid breaking common customizations.
<IfModule mod_headers.c>
Header always set X-Content-Type-Options "nosniff"
Header always set Referrer-Policy "strict-origin-when-cross-origin"
Header always set Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=()"

# Prevent clickjacking on the OpenCATS UI.
# Note: /careers/ intentionally unsets this header in careers/.htaccess to allow embedding Career Portal into external websites using an iframe.
Header always set X-Frame-Options "SAMEORIGIN"
</IfModule>
5 changes: 5 additions & 0 deletions careers/.htaccess
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# The Career Portal might be embedded into external websites using an iframe.
# Allow embedding by unsetting the clickjacking protection header that is set globally.
<IfModule mod_headers.c>
Header always unset X-Frame-Options
</IfModule>
Loading