@@ -23,7 +23,8 @@ http {
add_header X-XSS-Protection "1; mode=block" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "no-referrer" always;
- add_header Content-Security-Policy "self" always;
+ # erg.. fix this eventually.
+ add_header Content-Security-Policy 'self' always;
# http://ja13.org and https://ja13.org
server {