-
-
Notifications
You must be signed in to change notification settings - Fork 4.7k
Closed
Labels
Milestone
Description
Steps to reproduce
- go to settings => overview
- see result of the Security & setup warnings
Expected behaviour
If setting of headers in .htaccess is not possible, the security headers are set in lib/private/legacy/response.php => addSecurityHeaders()
Actual behaviour
The header Referrer-Policy "no-referrer" is only set in .htaccess
Server configuration
Operating system: Linux 3.18.114-pvops-xen-x64
Web server: Apache 2.4.35 with FastCGI activated
Database: MySQL 5.6.19
PHP version: 7.2.11
Nextcloud version: 15.0.0.7 (but the problem applies to 14.x as well)
Updated from an older Nextcloud/ownCloud or fresh install: updated
Where did you install Nextcloud from: 14.0.4
Client configuration
Browser: Chrome 70.0.3538.102
Operating system: macOS 10.13.6