[dreamwidth/dreamwidth] 58f1e9: Update origin policy
Branch: refs/heads/main Home: https://github.com/dreamwidth/dreamwidth Commit: 58f1e9ae34fdd53a861b5dae1e35fd57dc955024 https://github.com/dreamwidth/dreamwidth/commit/58f1e9ae34fdd53a861b5dae1e35fd57dc955024 Author: Mark Smith mark@dreamwidth.org Date: 2026-06-03 (Wed, 03 Jun 2026)
Changed paths: M cgi-bin/Apache/LiveJournal.pm M cgi-bin/Plack/Middleware/DW/SecurityHeaders.pm
Log Message:
Update origin policy
This moves us to strict-origin-when-cross-origin which is probably what will fix embed issues with older embeds. It means that when we're referring to content that is not on our own service, we only send the domain -- so they can't see precisely what entry referred them, but at least they know it's dreamwidth.
To unsubscribe from these emails, change your notification settings at https://github.com/dreamwidth/dreamwidth/settings/notifications
