diff --git a/_headers b/_headers new file mode 100644 index 0000000..63c1e97 --- /dev/null +++ b/_headers @@ -0,0 +1,11 @@ +/* + Report-To: '{"group":"default","max_age":31536000,"endpoints":[{"url":"https://katriel.report-uri.com/a/d/g"}],"include_subdomains":true}' + + NEL: '{"report_to":"default","max_age":31536000,"include_subdomains":true}' + + Content-Security-Policy: default-src 'none'; script-src 'report-sample' 'self' https://cdn.ampproject.org; style-src 'report-sample' 'self' https://fonts.googleapis.com 'sha256-0+eUWXEzIzayXtwbs4qgGqcUroB222vieZ1QP7fQ6so=' 'sha256-PGXOJdY/N14DFaumETOevn4XJmmnEBUq35DEE7PwXzI=' 'sha256-ERzu1wweqgxgsinDVzlR2NhKKo4DjFon34MAwo+xvWM=' 'sha256-PQYtiIZYTtt8E9hjj3jfnmSZ5QHVzfzJgN3hZ+uDKA0='; object-src 'none'; base-uri 'self'; connect-src 'self'; font-src 'self' https://fonts.gstatic.com; form-action 'self'; frame-ancestors 'none'; frame-src 'self'; img-src 'self' https://*.cloudfront.net; manifest-src 'self'; media-src 'self'; report-uri https://katriel.report-uri.com/r/d/csp/reportOnly; report-to report-uri; worker-src 'none'; + + X-Content-Type-Options: nosniff + X-Frame-Options: DENY + X-XSS-Protection: 1;mode=block + Referrer-Policy: no-referrer, strict-origin-when-cross-origin \ No newline at end of file diff --git a/index.html b/index.html index d56e54a..1a5096f 100644 --- a/index.html +++ b/index.html @@ -48,11 +48,12 @@ - + + + - - + +