On this page can set the Content Security Policy (CSP) and various other security HTTP headers.

The CSP header comes with default policy

Content-Security-Policy: default-src 'self' data: 'unsafe-inline' 'unsafe-eval'

not visible or editable in the GUI. The Domains Allowed field values extend the policy with external source domain directives.

The Other Headers section allows adding miscellaneous headers, the format required is
Header-Name:header value #1;header value #2;
We set the following security headers by default:

Can add up to 20 additional headers in this section. This may be extended in future releases.

