[general] host = "0.0.0.0" port = 8080 root = "/public" log-level = "error" compression = true [[advanced.headers]] source = "**/*" [advanced.headers.headers] "X-Frame-Options" = "DENY" "X-Content-Type-Options" = "nosniff" "Referrer-Policy" = "strict-origin-when-cross-origin" "Content-Security-Policy" = "default-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:;"