# security-headers v1 (scripts/web/security_headers.py) /* Strict-Transport-Security: max-age=31536000 X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN Referrer-Policy: strict-origin-when-cross-origin Cross-Origin-Resource-Policy: cross-origin Content-Security-Policy: frame-ancestors 'self'; object-src 'none'; base-uri 'self'; upgrade-insecure-requests /embed/* ! X-Frame-Options ! Content-Security-Policy # /security-headers /* X-Content-Type-Options: nosniff Referrer-Policy: strict-origin-when-cross-origin /town.js Cache-Control: public, max-age=300 /app.js Cache-Control: public, max-age=300 /style.css Cache-Control: public, max-age=300 /seed/* Cache-Control: public, max-age=86400