| Index: modules/web/templates/adblockplus.org.conf.erb | 
| =================================================================== | 
| --- a/modules/web/templates/adblockplus.org.conf.erb | 
| +++ b/modules/web/templates/adblockplus.org.conf.erb | 
| @@ -1,12 +1,12 @@ | 
| # XSS and clickjacking prevention headers | 
|  | 
| set $csp_frame ""; | 
| -if ($uri ~ ^/(:?\w\w(_\w\w)?/)?(?:index|firefox|chrome|opera|android|internet-explorer|safari|yandex-browser|maxthon)?$) | 
| +if ($uri ~ ^/(:?\w\w(_\w\w)?/)?(?:index|firefox|chrome|opera|android|internet-explorer|safari|yandex-browser|maxthon)?$|^/blog/) | 
| { | 
| set $csp_frame "; frame-src www.youtube-nocookie.com;"; | 
| } | 
| add_header Content-Security-Policy "default-src 'self'; img-src * data:; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval' $csp_frame"; | 
| add_header X-Frame-Options "sameorigin"; | 
|  | 
| # User agent sniffing | 
|  | 
|  |