diff --git a/app/__init__.py b/app/__init__.py index 2c123f71b..b9c768875 100644 --- a/app/__init__.py +++ b/app/__init__.py @@ -286,10 +286,13 @@ def init_app(app): @app.after_request def after_request(response): response.headers.add("X-Content-Type-Options", "nosniff") + + # Some dynamic scan findings response.headers.add("Cross-Origin-Opener-Policy", "same-origin") response.headers.add("Cross-Origin-Embedder-Policy", "require-corp") response.headers.add("Cross-Origin-Resource-Policy", "same-origin") response.headers.add("Cross-Origin-Opener-Policy", "same-origin") + response.headers.pop("Server", None) return response