From 6f3bb25b092cf33160d1a8d2071f7ca4e5cedcaa Mon Sep 17 00:00:00 2001 From: El RIDO Date: Fri, 16 Apr 2021 20:25:50 +0200 Subject: [PATCH 1/2] disable Google FloC --- lib/Controller.php | 1 + 1 file changed, 1 insertion(+) diff --git a/lib/Controller.php b/lib/Controller.php index bc23a52a..bfa29b1d 100644 --- a/lib/Controller.php +++ b/lib/Controller.php @@ -349,6 +349,7 @@ class Controller header('Cross-Origin-Resource-Policy: same-origin'); header('Cross-Origin-Embedder-Policy: require-corp'); header('Cross-Origin-Opener-Policy: same-origin'); + header('Permissions-Policy: interest-cohort=()'); header('Referrer-Policy: no-referrer'); header('X-Content-Type-Options: nosniff'); header('X-Frame-Options: deny'); From 5f4200c721be070162981878dff30ade1bcde89f Mon Sep 17 00:00:00 2001 From: El RIDO Date: Sat, 17 Apr 2021 08:39:35 +0200 Subject: [PATCH 2/2] document change --- CHANGELOG.md | 1 + 1 file changed, 1 insertion(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 00f5f21c..b3278931 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,6 +3,7 @@ * **1.4 (not yet released)** * ADDED: Translation for Estonian * ADDED: new HTTP headers improving security (#765) + * ADDED: Opt-out of federated learning of cohorts (FLoC) (#776) * CHANGED: Language selection cookie only transmitted over HTTPS (#472) * **1.3.5 (2021-04-05)** * ADDED: Translation for Hebrew, Lithuanian, Indonesian and Catalan