summaryrefslogtreecommitdiff
path: root/doc/snac.8
diff options
context:
space:
mode:
Diffstat (limited to 'doc/snac.8')
-rw-r--r--doc/snac.86
1 files changed, 4 insertions, 2 deletions
diff --git a/doc/snac.8 b/doc/snac.8
index 05991e1..f58ad45 100644
--- a/doc/snac.8
+++ b/doc/snac.8
@@ -179,9 +179,11 @@ By setting this to true, no email notification will be sent for any user.
.It Ic disable_inbox_collection
By setting this to true, no inbox collection is done. Inbox collection helps
being discovered from remote instances, but also increases network traffic.
-.It http_headers
+.It Ic http_headers
If you need to add more HTTP response headers for whatever reason, you can
-fill this object with the required header/value pairs.
+fill this object with the required header/value pairs. For example, for enhanced
+XSS security, you can set the "Content-Security-Policy" header to "script-src ;"
+to be totally sure that no JavaScript is executed.
.It Ic show_instance_timeline
If this is set to true, the instance base URL will show a timeline with the latest
user posts instead of the default greeting static page. If other information