diff --git a/data/etc/apache2/conf-available/freedombox.conf b/data/etc/apache2/conf-available/freedombox.conf index f650cab65..6e108ec18 100644 --- a/data/etc/apache2/conf-available/freedombox.conf +++ b/data/etc/apache2/conf-available/freedombox.conf @@ -11,6 +11,45 @@ Header set Strict-Transport-Security "max-age=31536000; includeSubDomains" env=H RedirectMatch "^/$" "/plinth" RedirectMatch "^/freedombox" "/plinth" +## +## Disable sending Referer (sic) header from FreedomBox web interface to +## external websites. This improves privacy by not disclosing FreedomBox +## domains/URLs to external domains. Apps such as blogs which want to popularize +## themselves with referrer header may still do so. +## +## A strict Content Security Policy. +## - @fonts are allowed only from FreedomBox itself. +## - /