Transport and headers of this site
Every response from this site carries a fixed set of security headers. They can be checked from outside, without you having to take our word for it.
- Strict-Transport-Security enforces the encrypted connection, including subdomains.
- frame-ancestors and X-Frame-Options prevent embedding in third-party pages.
- base-uri and form-action tie the base URL and form targets to our own origin; camera, microphone and location are switched off via the permissions policy.
- The content security policy deliberately stays wide for scripts while no nonce chain exists — that is written as a comment at the place itself, not only here.
Proof in next.config.ts