diff --git a/lib/ret_web/router.ex b/lib/ret_web/router.ex index d98429be4..fa5009584 100644 --- a/lib/ret_web/router.ex +++ b/lib/ret_web/router.ex @@ -4,12 +4,20 @@ defmodule RetWeb.Router do use Sentry.Plug pipeline :secure_headers do - plug(:put_secure_browser_headers) + plug(:put_secure_browser_headers, %{ + "cross-origin-opener-policy" => "same-origin", + "cross-origin-resource-policy" => "require-corp" + }) + plug(RetWeb.Plugs.AddCSP) end pipeline :strict_secure_headers do - plug(:put_secure_browser_headers) + plug(:put_secure_browser_headers, %{ + "cross-origin-opener-policy" => "same-origin", + "cross-origin-resource-policy" => "require-corp" + }) + plug(RetWeb.Plugs.AddCSP, strict: true) end