From ff75f1543a81d02f593924a952d0708457dd097a Mon Sep 17 00:00:00 2001 From: madrilene Date: Tue, 25 Jun 2024 15:02:34 +0200 Subject: [PATCH] Removed block-all-mixed-content since modern browsers now upgrade insecure requests where possible --- netlify.toml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/netlify.toml b/netlify.toml index 89e8aec..89e1130 100644 --- a/netlify.toml +++ b/netlify.toml @@ -7,7 +7,7 @@ package = "netlify-plugin-cache" [[headers]] for = "/*" [headers.values] - Content-Security-Policy = "upgrade-insecure-requests; block-all-mixed-content;" + Content-Security-Policy = "upgrade-insecure-requests;" X-Content-Type-Options = "nosniff" X-Frame-Options = "DENY" X-XSS-Protection = "1; mode=block"