| Index: modules/web/templates/adblockplus.org.conf.erb |
| =================================================================== |
| --- a/modules/web/templates/adblockplus.org.conf.erb |
| +++ b/modules/web/templates/adblockplus.org.conf.erb |
| @@ -1,16 +1,16 @@ |
| # XSS and clickjacking prevention headers |
| set $csp_frame ""; |
| if ($uri ~ ^/(:?\w\w(_\w\w)?/)?(?:index|firefox|chrome|opera|android|internet-explorer|safari|yandex-browser|maxthon)?$) |
| { |
| set $csp_frame "; frame-src www.youtube-nocookie.com;"; |
| } |
| -add_header Content-Security-Policy "default-src \'self\'; img-src * data:; style-src \'self\' \'unsafe-inline\'; script-src \'self\' \'unsafe-inline\' \'unsafe-eval\' $csp_frame"; |
| +add_header Content-Security-Policy "default-src 'self'; img-src * data:; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval' $csp_frame"; |
| add_header X-Frame-Options "sameorigin"; |
| # User agent sniffing |
| set $user_agent ""; |
| if ($http_user_agent ~ \bGecko/\d+) |
| { |
| set $user_agent "firefox"; |
| @@ -51,17 +51,17 @@ if ($http_user_agent ~ \bYaBrowser/\d+) |
| { |
| set $user_agent "yandex-browser"; |
| } |
| if ($http_user_agent ~ \bMaxthon/\d+) |
| { |
| set $user_agent "maxthon"; |
| } |
| -sub_filter \' id="content" class="\' \' id="content" class="ua-$user_agent \'; |
| +sub_filter ' id="content" class="' ' id="content" class="ua-$user_agent '; |
| set $index_page "firefox"; |
| if ($user_agent != "") |
| { |
| set $index_page $user_agent; |
| } |
| # Various redirects |