| Line 9... |
Line 9... |
| 9 |
header("X-XSS-Protection: 1; mode=block");
|
9 |
header("X-XSS-Protection: 1; mode=block");
|
| 10 |
header("Access-Control-Allow-Origin: *");
|
10 |
header("Access-Control-Allow-Origin: *");
|
| 11 |
header("Referrer-Policy: no-referrer");
|
11 |
header("Referrer-Policy: no-referrer");
|
| 12 |
header("X-Frame-Options: SAMEORIGIN");
|
12 |
header("X-Frame-Options: SAMEORIGIN");
|
| 13 |
header("Set-Cookie: ^(.*)$ $1;HttpOnly;Secure");
|
13 |
header("Set-Cookie: ^(.*)$ $1;HttpOnly;Secure");
|
| 14 |
header("Content-Security-Policy: default-src 'none'; connect-src 'self'; font-src https://use.fontawesome.com https://fonts.gstatic.com/; form-action 'self'; img-src 'self' data: https://assets.sheetmusicplus.com https://d115fki8ibznml.cloudfront.net https://i5.wal.co https://i5.walmartimages.com https://images.samash.com https://img.discogs.com https://thumbs1.ebaystatic.com https://thumbs2.ebaystatic.com https://thumbs3.ebaystatic.com https://thumbs4.ebaystatic.com https://www.musicnotes.com https://www.secondspin.com; script-src 'self' 'unsafe-inline' https://ajax.googleapis.com/ajax/libs/jquery/3.4.0/jquery.min.js https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.14.7/umd/popper.min.js https://maxcdn.bootstrapcdn.com/bootstrap/4.3.1/js/bootstrap.min.js; style-src 'self' 'unsafe-inline' https://maxcdn.bootstrapcdn.com/bootstrap/4.3.1/css/ https://use.fontawesome.com/releases/v5.8.1/css/ https://fonts.googleapis.com/;frame-ancestors 'self'");
|
14 |
header("Content-Security-Policy: default-src 'none'; connect-src 'self'; font-src https://use.fontawesome.com https://fonts.gstatic.com/; form-action 'self'; img-src 'self' data: https://assets.sheetmusicplus.com https://d115fki8ibznml.cloudfront.net https://i5.wal.co https://i5.walmartimages.com https://images.samash.com https://img.discogs.com https://thumbs1.ebaystatic.com https://thumbs2.ebaystatic.com https://thumbs3.ebaystatic.com https://thumbs4.ebaystatic.com https://www.musicnotes.com https://www.secondspin.com https://www.fye.com; script-src 'self' 'unsafe-inline' https://ajax.googleapis.com/ajax/libs/jquery/3.4.0/jquery.min.js https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.14.7/umd/popper.min.js https://maxcdn.bootstrapcdn.com/bootstrap/4.3.1/js/bootstrap.min.js; style-src 'self' 'unsafe-inline' https://maxcdn.bootstrapcdn.com/bootstrap/4.3.1/css/ https://use.fontawesome.com/releases/v5.8.1/css/ https://fonts.googleapis.com/;frame-ancestors 'self'");
|
| 15 |
}
|
15 |
}
|