generated from shgysk8zer0/jekyll-template
-
-
Notifications
You must be signed in to change notification settings - Fork 1
/
_headers
68 lines (56 loc) · 5.58 KB
/
_headers
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
/
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-XSS-Protection: 1; mode=block
Referrer-Policy: no-referrer
Link: </css/index.min.css>; rel=preload; as=style; referrerpolicy=no-referrrer;
Link: <https://unpkg.com/@shgysk8zer0/[email protected]/all.min.js>; rel=preload; as=script; referrerpolicy=no-referrrer; crossorigin=anonymous;
Link: <https://unpkg.com/@shgysk8zer0/[email protected]/harden.js>; rel=preload; as=script; referrerpolicy=no-referrrer; crossorigin=anonymous;
Link: </js/index.min.js>; rel=preload; as=script; referrerpolicy=no-referrrer;
Content-Security-Policy: default-src 'self'; img-src *; script-src 'self' unpkg.com/ www.google-analytics.com www.googletagmanager.com www.gstatic.com/firebasejs/ 'nonce-c23ddb4e-a8ec-44f0-ad77-d1ac60938c7e'; style-src 'self' cdn.kernvalley.us unpkg.com/ blob:; connect-src 'self' store.kernvalley.us apps.kernvalley.us ads.kernvalley.us/api/ api.github.com/users/ api.openweathermap.org/data/2.5/weather www.google-analytics.com/ www.googletagmanager.com/gtag/ firestore.googleapis.com unpkg.com/@shgysk8zer0/ unpkg.com/@kernvalley/; font-src cdn.kernvalley.us; media-src *; frame-src www.youtube-nocookie.com 'self'; form-action 'self'; manifest-src 'self'; worker-src 'self'; reflected-xss block; upgrade-insecure-requests; block-all-mixed-content; disown-opener; trusted-types default empty#html empty#script sanitizer-raw#html purify-raw#html purify#html weather-current#html youtube#script-url pwa-install share-to-buttons#html github-user#html ga#script-url goog#html; require-trusted-types-for 'script';
/:placeholder/
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-XSS-Protection: 1; mode=block
Referrer-Policy: no-referrer
Feature-Policy: geolocation 'self';
Link: </css/index.min.css>; rel=preload; as=style; referrerpolicy=no-referrrer;
Link: <https://unpkg.com/@shgysk8zer0/[email protected]/all.min.js>; rel=preload; as=script; referrerpolicy=no-referrrer; crossorigin=anonymous;
Link: <https://unpkg.com/@shgysk8zer0/[email protected]/harden.js>; rel=preload; as=script; referrerpolicy=no-referrrer; crossorigin=anonymous;
Content-Security-Policy: default-src 'self'; img-src * data: blob:; script-src 'self' unpkg.com/ www.google-analytics.com www.googletagmanager.com js.stripe.com/v3/ www.gstatic.com/firebasejs/ 'nonce-c23ddb4e-a8ec-44f0-ad77-d1ac60938c7e'; style-src 'self' cdn.kernvalley.us unpkg.com/ blob:; connect-src 'self' cdn.kernvalley.us store.kernvalley.us apps.kernvalley.us ads.kernvalley.us/api/ api.github.com/users/ api.openweathermap.org/data/2.5/weather www.google-analytics.com/ www.googletagmanager.com/gtag/ firestore.googleapis.com unpkg.com/@shgysk8zer0/ unpkg.com/@kernvalley/; font-src cdn.kernvalley.us; media-src *; frame-src www.youtube-nocookie.com maps.kernvalley.us/embed https://calendar.google.com/calendar/embed js.stripe.com/v3/; form-action 'self'; manifest-src 'self'; worker-src 'self'; reflected-xss block; upgrade-insecure-requests; block-all-mixed-content; disown-opener; trusted-types default empty#html empty#script sanitizer-raw#html purify-raw#html purify#html weather-current#html youtube#script-url github-user#html pwa-install share-to-buttons#html ga#script-url goog#html goog-cal#script-url; require-trusted-types-for 'script';
/mayors/events.json
Content-Security-Policy: default-src 'self'
Access-Control-Allow-Origin: *
/reset
Referrer-Policy: no-referrer
Clear-Site-Data: "cache", "cookies", "storage"
Content-Security-Policy: default-src 'self'; script-src 'self' cdn.kernvalley.us;
/embed/
Referrer-Policy: no-referrer
X-Frame-Options: ALLOW
Link: <https://unpkg.com/@shgysk8zer0/[email protected]/all.min.js> rel=preload; as=script; crossorigin=anonymous; referrerpolicy=no-referrer;
Link: <https://unpkg.com/@shgysk8zer0/[email protected]/harden.js> rel=preload; as=script; crossorigin=anonymous; referrerpolicy=no-referrer;
Link: </events.json>; rel=preload; as=fetch; type=application/json; referrerpolicy=no-referrer;
Content-Security-Policy: default-src 'none'; img-src 'self' *; style-src 'self' unpkg.com/@shgysk8zer0/ unpkg.com/@kernvalley/ blob:; script-src 'self' unpkg.com/@shgysk8zer0/ unpkg.com/@kernvalley/; font-src cdn.kernvalley.us/fonts/; connect-src 'self' whiskeyflatdays.com/events.json unpkg.com/@shgysk8zer0/ unpkg.com/@kernvalley/; frame-ancestors *; upgrade-insecure-requests; block-all-mixed-content; disown-opener; trusted-types empty#html empty#script sanitizer-raw#html wfd-events#html; require-trusted-types-for 'script';
/events.json
Access-Control-Allow-Origin: *
Content-Security-Policy: default-src: 'none'
TK: N
/mayors/embed/
Referrer-Policy: no-referrer
X-Frame-Options: ALLOW
Content-Security-Policy: default-src 'none'; img-src 'self' *; style-src 'self' unpkg.com/@shgysk8zer0/ unpkg.com/@kernvalley/ blob:; script-src 'self' unpkg.com/@shgysk8zer0/ unpkg.com/@kernvalley/; font-src cdn.kernvalley.us/fonts/; connect-src 'self' whiskeyflatdays.com/mayors/events.json; frame-ancestors *; upgrade-insecure-requests; block-all-mixed-content; disown-opener; trusted-types empty#html empty#script sanitizer-raw#html; require-trusted-types-for 'script';
/mayors/events.json
Content-Security-Policy: default-src 'none'
Access-Control-Allow-Origin: *
/img/*
Access-Control-Allow-Origin: *
Content-Security-Policy: default-src: 'none'
TK: N
/service-worker.js
Referrer-Policy: no-referrer
Content-Security-Policy: default-src 'self'; connect-src *; script-src 'self' cdn.kernvalley.us/service-worker.js;
Link: </sw-config.js>; rel=preload; as=script;
Link: <//cdn.kernvalley.us/service-worker.js>; rel=preload; as=script;
/*
X-Content-Type-Options: nosniff