diff --git a/app/templates/element/httpHeaders.php b/app/templates/element/httpHeaders.php index bae379c6..4e585767 100644 --- a/app/templates/element/httpHeaders.php +++ b/app/templates/element/httpHeaders.php @@ -36,8 +36,8 @@ header("X-Content-Type-Options: nosniff"); header("Permissions-Policy: accelerometer=(),autoplay=(),camera=(),cross-origin-isolated=(),display-capture=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),keyboard-map=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=(),gamepad=(),hid=(),idle-detection=(),interest-cohort=(),serial=()"); - header("Cross-Origin-Opener-Policy: same-origin"); - header("Cross-Origin-Embedder-Policy: require-corp"); + header('Cross-Origin-Opener-Policy: "same-origin"'); + header('Cross-Origin-Embedder-Policy: "require-corp"'); header("X-Permitted-Cross-Domain-Policies: none"); // Add X-UA-Compatible header for IE