michael,
@michael@thms.uk avatar

Re 4.1.3: The release notes recommend:

“The recommended configuration for reverse proxies has been updated. [...] The change is about setting Content-Security-Policy: default-src 'none'; form-action 'none' and X-Content-Type-Options: nosniff on assets.”

This might be a bit confusing, because of the terminology:

Those two lines ought to to into the location ~ ^/system/ block - NOT location ~ ^/assets/

https://github.com/mastodon/mastodon/pull/25756/commits/8060ab945392b2fa88d75a49a09a4c5895e72f71

  • @FoW@netsphere.one avatar
    FoW
  • All
  • Subscribed
  • Moderated
  • Favorites
  • mastodon
  • Durango
  • DreamBathrooms
  • khanakhh
  • GTA5RPClips
  • osvaldo12
  • magazineikmin
  • mdbf
  • InstantRegret
  • rosin
  • Youngstown
  • slotface
  • everett
  • kavyap
  • ngwrru68w68
  • megavids
  • modclub
  • tester
  • tacticalgear
  • cubers
  • thenastyranch
  • cisconetworking
  • ethstaker
  • Leos
  • provamag3
  • normalnudes
  • anitta
  • JUstTest
  • lostlight
  • All magazines