## ## Enable HSTS, even for subdomains. ## Header set Strict-Transport-Security "max-age=31536000; includeSubDomains" env=HTTPS ## ## Redirect traffic on home to /plinth as part of turning the machine ## into FreedomBox server. Plinth then acts as a portal to reach all ## other services. ## RedirectMatch "^/$" "/plinth" RedirectMatch "^/freedombox" "/plinth" ## ## Disable sending Referer (sic) header from FreedomBox web interface to ## external websites. This improves privacy by not disclosing FreedomBox ## domains/URLs to external domains. Apps such as blogs which want to popularize ## themselves with referrer header may still do so. ## ## A strict Content Security Policy. ## - @fonts are allowed only from FreedomBox itself. ## - /