]> source.dussan.org Git - nextcloud-server.git/commitdiff
Set Referrer-Policy also in addSecurityHeaders() 12738/head
authorPeter Kraume <peter.kraume@gmx.de>
Tue, 27 Nov 2018 15:34:54 +0000 (16:34 +0100)
committerBackportbot <backportbot-noreply@rullzer.com>
Thu, 29 Nov 2018 16:48:12 +0000 (16:48 +0000)
Fix: #12689
Signed-off-by: Peter Kraume <peter.kraume@gmx.de>
lib/private/legacy/response.php

index 93023f61e995e8d15ad0e2412be2885b18334a07..bfee5aadb4dc697fbffc44868fe2031ac98965fd 100644 (file)
@@ -104,6 +104,7 @@ class OC_Response {
                        header('X-Robots-Tag: none'); // https://developers.google.com/webmasters/control-crawl-index/docs/robots_meta_tag
                        header('X-Download-Options: noopen'); // https://msdn.microsoft.com/en-us/library/jj542450(v=vs.85).aspx
                        header('X-Permitted-Cross-Domain-Policies: none'); // https://www.adobe.com/devnet/adobe-media-server/articles/cross-domain-xml-for-streaming.html
+                       header('Referrer-Policy: no-referrer'); // https://www.w3.org/TR/referrer-policy/
                }
        }