Skip to content

Conversation

@XhmikosR
Copy link
Contributor

This will use the defaults plus HSTS for 2 years so that we can preload the domain after this is merged (https://hstspreload.org/) and Referrer-Policy set to strict-origin-when-cross-origin

Let me know if you want me to make any changes @sagarkarira :)

PS. I didn't add CSP, we could add it later if you want.

Fixes #38

@vercel
Copy link

vercel bot commented Mar 21, 2020

This pull request is being automatically deployed with ZEIT Now (learn more).
To see the status of your deployment, click below or on the icon next to each commit.

🔍 Inspect: https://zeit.co/sagark/coronavirus-tracker/l574xlxp1
✅ Preview: https://coronavirus-tracker-git-fork-xhmikosr-helmet.sagark.now.sh

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Tighten HTTP headers

2 participants