From: Rigel Kent Date: Tue, 20 Mar 2018 16:28:41 +0000 (+0100) Subject: Selective route permission to use embeds, fixes #322 in a better way (#364) X-Git-Tag: v1.0.0-beta.2~79 X-Git-Url: https://git.librecmc.org/?a=commitdiff_plain;h=d40cd86bf56973d7217ad44737e3890b6e7f1ad5;p=oweals%2Fpeertube.git Selective route permission to use embeds, fixes #322 in a better way (#364) --- diff --git a/support/nginx/peertube b/support/nginx/peertube index e94eac5e8..bde0b18e8 100644 --- a/support/nginx/peertube +++ b/support/nginx/peertube @@ -38,6 +38,7 @@ server { # resolver_timeout 5s; add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"; + add_header X-Frame-Options DENY; add_header X-Content-Type-Options nosniff; add_header X-XSS-Protection "1; mode=block"; add_header X-Robots-Tag none; @@ -103,6 +104,11 @@ server { alias /var/www/peertube/storage/videos; } + # Allow embeds + location /videos/embed { + proxy_hide_header X-Frame-Options; + } + # Websocket tracker location /tracker/socket { # Peers send a message to the tracker every 15 minutes