summaryrefslogtreecommitdiff
path: root/doc
diff options
context:
space:
mode:
authorGravatar default2025-02-13 19:44:21 +0100
committerGravatar default2025-02-13 19:44:21 +0100
commit292b2fd1224a40fd3fa5bc33248a7b11316abc22 (patch)
tree98eed1cf462048ee337e27cdc6652b02e1dadc50 /doc
parentDrop SVG attachments, as they may include JavaScript. (diff)
downloadpenes-snac2-292b2fd1224a40fd3fa5bc33248a7b11316abc22.tar.gz
penes-snac2-292b2fd1224a40fd3fa5bc33248a7b11316abc22.tar.xz
penes-snac2-292b2fd1224a40fd3fa5bc33248a7b11316abc22.zip
Force the Content-Security-Policy header, instead of just suggesting it in the docs.
Diffstat (limited to 'doc')
-rw-r--r--doc/snac.84
1 files changed, 1 insertions, 3 deletions
diff --git a/doc/snac.8 b/doc/snac.8
index c0a110c..7a7352c 100644
--- a/doc/snac.8
+++ b/doc/snac.8
@@ -198,9 +198,7 @@ By setting this to true, no inbox collection is done. Inbox collection helps
198being discovered from remote instances, but also increases network traffic. 198being discovered from remote instances, but also increases network traffic.
199.It Ic http_headers 199.It Ic http_headers
200If you need to add more HTTP response headers for whatever reason, you can 200If you need to add more HTTP response headers for whatever reason, you can
201fill this object with the required header/value pairs. For example, for enhanced 201fill this object with the required header/value pairs.
202XSS security, you can set the "Content-Security-Policy" header to "script-src ;"
203to be totally sure that no JavaScript is executed.
204.It Ic show_instance_timeline 202.It Ic show_instance_timeline
205If this is set to true, the instance base URL will show a timeline with the latest 203If this is set to true, the instance base URL will show a timeline with the latest
206user posts instead of the default greeting static page. If other information 204user posts instead of the default greeting static page. If other information