aboutsummaryrefslogtreecommitdiff
path: root/doc
diff options
context:
space:
mode:
authordefault <nobody@localhost>2025-02-13 19:44:21 +0100
committerdefault <nobody@localhost>2025-02-13 19:44:21 +0100
commit292b2fd1224a40fd3fa5bc33248a7b11316abc22 (patch)
tree98eed1cf462048ee337e27cdc6652b02e1dadc50 /doc
parente237a35f0d51683511e87e68c2fe3fd9bdf3ef9e (diff)
Force the Content-Security-Policy header, instead of just suggesting it in the docs.
Diffstat (limited to 'doc')
-rw-r--r--doc/snac.84
1 files changed, 1 insertions, 3 deletions
diff --git a/doc/snac.8 b/doc/snac.8
index c0a110c..7a7352c 100644
--- a/doc/snac.8
+++ b/doc/snac.8
@@ -198,9 +198,7 @@ By setting this to true, no inbox collection is done. Inbox collection helps
being discovered from remote instances, but also increases network traffic.
.It Ic http_headers
If you need to add more HTTP response headers for whatever reason, you can
-fill this object with the required header/value pairs. For example, for enhanced
-XSS security, you can set the "Content-Security-Policy" header to "script-src ;"
-to be totally sure that no JavaScript is executed.
+fill this object with the required header/value pairs.
.It Ic show_instance_timeline
If this is set to true, the instance base URL will show a timeline with the latest
user posts instead of the default greeting static page. If other information