diff --git a/http/response/builder.go b/http/response/builder.go index 43e64c88..8335d0ad 100644 --- a/http/response/builder.go +++ b/http/response/builder.go @@ -97,6 +97,7 @@ func (b *Builder) writeHeaders() { b.headers["X-Content-Type-Options"] = "nosniff" b.headers["X-Frame-Options"] = "DENY" b.headers["Content-Security-Policy"] = "default-src 'self'; img-src * data:; media-src *; frame-src *" + b.headers["Referrer-Policy"] = "no-referrer" for key, value := range b.headers { b.w.Header().Set(key, value)