Using Adobe products like PDF, Flash, etc.?
You can implement this header to instruct the browser on how to handle the requests over a cross-domain. By implementing this header, you restrict loading your site’s assets from other domains to avoid resource abuse.
There are a few options available.
Value | Description |
none | no policy is allowed |
master-only | allow only the master policy |
all | everything is allowed |
by-content-only | Allow only a certain type of content. Example – XML |
by-ftp-only | applicable only for an FTP server |
Apache
If you don’t want to allow any policy.
Header set X-Permitted-Cross-Domain-Policies \"none\"
You should see the header like the following.
data:image/s3,"s3://crabby-images/9dd8a/9dd8a5c6564e54de15eda222f1b148e03d8966fc" alt="\"\""
Nginx
And, let’s say you need to implement master-only then add the following in nginx.conf
under server
block.
add_header X-Permitted-Cross-Domain-Policies master-only;
And the result.
data:image/s3,"s3://crabby-images/969c4/969c4e49f7a0b43fcba5b690684d2224159a5b6d" alt="\"\""