# The "Referrer-Policy" HTTP header is not set to "no-referrer"

**URL:** <https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613>\
**Category:** ℹ️ Support\
**Tags:** update\_problems, nc14\
**Created:** [September 11, 2018, 3:01am UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613 "2018-09-11T03:01:21Z")\
**Posts on this page:** 20\
**Page:** 3

<div class="post-metadata">

**Author:** ![XDavidT](https://help.nextcloud.com/user_avatar/help.nextcloud.com/xdavidt/32/9926_2.png) [@XDavidT](https://help.nextcloud.com/u/XDavidT)\
**Post date:** [November 22, 2018, 12:42pm UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/42 "2018-11-22T12:42:12Z")

</div>

I also have:

> The “Referrer-Policy” HTTP header is not set to “no-referrer”, “no-referrer-when-downgrade”, “strict-origin” or “strict-origin-when-cross-origin”. This can leak referer information.

But I’m using shared host and manage all from cloudflare:  
 ![](https://snag.gy/Rs7fy6.jpg)  
What to choose ? is this OK ?

---

<div class="post-metadata">

**Author:** ![voidoid3](https://help.nextcloud.com/letter_avatar/voidoid3/32/5_5575768a8748004e209b776fc1b2916d.png) [@voidoid3](https://help.nextcloud.com/u/voidoid3)\
**Post date:** [November 23, 2018, 3:04am UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/43 "2018-11-23T03:04:04Z")

</div>

So that I can remember for the future, here is what I did to correct this problem (I am running Ubuntu 16.04):

1. In /var/www/html/nextcloud/.htacess, I commented out: Header set Referrer-Policy "no-referrer"

2. In /etc/apache2/apache2.conf, I have the following:

\<IfModule mod\_headers.c\>

Header always add Strict-Transport-Security "max-age=15768000; includeSubDomains; preload"

Header always set Referrer-Policy "no referrer"

Header always set Referrer-Policy "strict-origin"

\</IfModule\>

This removes the warning.

I hope that this is helpful to someone.

---

<div class="post-metadata">

**Author:** ![rakekniven](https://help.nextcloud.com/user_avatar/help.nextcloud.com/rakekniven/32/67096_2.png) [@rakekniven](https://help.nextcloud.com/u/rakekniven)\
**Post date:** [November 23, 2018, 5:55pm UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/44 "2018-11-23T17:55:53Z")

</div>

I run a Raspberry Pi with ubuntu based linux.  
Til 14.04 I used following config line:

> Header always set Referrer-Policy “no-referrer”

This raised an security error.  
I changed it to:

> Header set Referrer-Policy “no-referrer”

Warning went away.

EDIT. Just checked it with Qualys:

 ![44](https://help.nextcloud.com/uploads/default/original/2X/6/6e58b07a32253df3ca7c6e46c9cd20ab4ef85497.png)

Happy 🙂

---

<div class="post-metadata">

**Author:** ![voidoid3](https://help.nextcloud.com/letter_avatar/voidoid3/32/5_5575768a8748004e209b776fc1b2916d.png) [@voidoid3](https://help.nextcloud.com/u/voidoid3)\
**Post date:** [November 23, 2018, 6:46pm UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/46 "2018-11-23T18:46:15Z")

</div>

I just tried that but it didn’t get me the A+. Which config file did you modify?

---

<div class="post-metadata">

**Author:** ![Schmu](https://help.nextcloud.com/user_avatar/help.nextcloud.com/schmu/32/7823_2.png) [@Schmu](https://help.nextcloud.com/u/Schmu)\
**Post date:** [November 23, 2018, 6:52pm UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/47 "2018-11-23T18:52:27Z")

</div>

Sorry if I’m mistaken, but AFAIK the ssltest from Qualys doesn’t refer to the header settings and only checks the SSL configuration regarding key exchange, cipher strength and so on like seen on the score bars in the screenshot.

For a real header configuration test you should navigate to the already linked site [https://securityheaders.com/](https://securityheaders.com/)

@voidoid3 there are guides for a good SSL configuration out there.

> **[HOWTO: A+ with all 100%’s on SSL Labs test using Nginx mainline & stable](https://community.letsencrypt.org/t/howto-a-with-all-100-s-on-ssl-labs-test-using-nginx-mainline-stable/55033)**
>
> Steps to get you all 100% and A+ using Nginx mainline & stable version Certificate Section This section is easy to get 100% on. Make sure your cert and chain are in the correct order. Don’t use SHA1 (use SHA256) for the signature algorithm. Use...

So simplified it’s mainly about disabling weaker ciphers and stronger key encryptions.

---

<div class="post-metadata">

**Author:** ![enoch85](https://help.nextcloud.com/user_avatar/help.nextcloud.com/enoch85/32/49403_2.png) [@enoch85](https://help.nextcloud.com/u/enoch85)\
**Post date:** [November 23, 2018, 9:32pm UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/48 "2018-11-23T21:32:48Z")

</div>

Actually **removing** the setting from Apache2 Vhost for Nextcloud solved the issue for me.

As it’s already set in .htaccess with 14.0.4 the check will fail if it’s set twice.

I might be wrong though, but it solved the issue for me at least.

---

<div class="post-metadata">

**Author:** ![voidoid3](https://help.nextcloud.com/letter_avatar/voidoid3/32/5_5575768a8748004e209b776fc1b2916d.png) [@voidoid3](https://help.nextcloud.com/u/voidoid3)\
**Post date:** [November 23, 2018, 10:49pm UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/49 "2018-11-23T22:49:56Z")

</div>

Thanks @Schmu. I’m still learning. At this point, I have an A rating with the following issue:

Content-Security-Policy This policy contains ‘unsafe-eval’ which is dangerous in the script-src directive.

Searching but not finding how to address this.

---

<div class="post-metadata">

**Author:** ![Schmu](https://help.nextcloud.com/user_avatar/help.nextcloud.com/schmu/32/7823_2.png) [@Schmu](https://help.nextcloud.com/u/Schmu)\
**Post date:** [November 24, 2018, 12:23pm UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/50 "2018-11-24T12:23:14Z")

</div>

Hi,

We are all still learning and there is no stop for that in the IT 🙂

Regarding the unsafe-eval:  
There is nothing you can do about that right now. This is a CSP setting which is required by Nextcloud itself or rather most of the NC apps.  
The developers are aware of that and try to remove all functions which require eval in the code, but it takes time.  
However they already implemented a small solution which drastically reduces the risk of that setting and therefore there should be no or hardly any danger.  
Don’t worry about it 🙂

As long as everything else of your header settings are fine, your site is preloaded with https and your ssl settings are good, you are pretty safe.

---

<div class="post-metadata">

**Author:** ![voidoid3](https://help.nextcloud.com/letter_avatar/voidoid3/32/5_5575768a8748004e209b776fc1b2916d.png) [@voidoid3](https://help.nextcloud.com/u/voidoid3)\
**Post date:** [November 24, 2018, 2:20pm UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/51 "2018-11-24T14:20:51Z")

</div>

@Schmu Thanks:)

---

<div class="post-metadata">

**Author:** ![rakekniven](https://help.nextcloud.com/user_avatar/help.nextcloud.com/rakekniven/32/67096_2.png) [@rakekniven](https://help.nextcloud.com/u/rakekniven)\
**Post date:** [November 25, 2018, 3:29pm UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/52 "2018-11-25T15:29:10Z")

</div>

You are absolutely right.  
For headers you should use check mentioned by you.

Did that and received an A.

 ![12](https://help.nextcloud.com/uploads/default/original/2X/5/5d3c8c17bb2f5952a6d420d03d52387e020a172e.png)

 ![19](https://help.nextcloud.com/uploads/default/original/2X/f/f1702626cc70f045f532b49a0e37fe7cae35dd67.png)

Do someone know what to add to solve the “Feature-Policy” thing?

---

<div class="post-metadata">

**Author:** ![Schmu](https://help.nextcloud.com/user_avatar/help.nextcloud.com/schmu/32/7823_2.png) [@Schmu](https://help.nextcloud.com/u/Schmu)\
**Post date:** [November 25, 2018, 7:11pm UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/53 "2018-11-25T19:11:17Z")

</div>

For “Feature-Policy” I added the following line to my nginx config (server block):  
`add_header Feature-Policy "accelerometer 'none'; autoplay 'self'; geolocation 'none'; midi 'none'; notifications 'self'; push 'self'; sync-xhr 'self'; microphone 'self'; camera 'self'; magnetometer 'none'; gyroscope 'none'; speaker 'self'; vibrate 'self'; fullscreen 'self'; payment 'none'; usb 'none'";`

You can and should adjust that to your needs 🙂

If you are aiming for A+: this won’t be possible due to the unsafe-eval. I’m capped with A as well.

---

<div class="post-metadata">

**Author:** ![Schmu](https://help.nextcloud.com/user_avatar/help.nextcloud.com/schmu/32/7823_2.png) [@Schmu](https://help.nextcloud.com/u/Schmu)\
**Post date:** [December 13, 2018, 10:58am UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/54 "2018-12-13T10:58:51Z")

</div>

Hello everyone,

I just wanted to post an update and let you know that the “unsafe-eval” Content Security Policy has been removed in NC15. So right now we can even receive an A+ at [securityheaders.com](http://securityheaders.com)

If you want to run a more complete test, I even suggest to go to:  
**[https://observatory.mozilla.org/](https://observatory.mozilla.org/)**

It has a more detailed overview for CSP as well.  
In case you wonder about a few missing CSP entries for your server, I reported that at Github already:

> <https://github.com/nextcloud/server/issues/13042>
>
> When scanning my NC server with:
> https://observatory.mozilla.org
> 
> I notice th…at a few (many?) CSPs are not set at all, although they can be found in the source code. 
> I noticed this phenomenon in NC14 already but thought, due to the planned rework of CSP with NC15, this might get "corrected" in this latest release. After a fresh upgrade to NC15 the above-mentioned site still reports some policies missing.
> 
> The output is:
> 
> \------------
> \*\*Content-Security-Policy:\*\*	default-src 'none';base-uri 'none';manifest-src 'self';script-src 'nonce-ZS \[...\] D0=';style-src 'self' 'unsafe-inline' 'unsafe-inline';img-src 'self' data: blob:;font-src 'self';connect-src 'self' ;media-src 'self' blob:;child-src 'self';
> 
> \-----------
> 
> The policies missing, although mentioned in the PHP file 
> \`nextcloud/lib/public/AppFramework/Http/EmptyContentSecurityPolicy.php\`:
> \- worker-src
> \- frame-ancestors
> \- frame-src
> 
> What could be added by this opportunity is:
> \- form-action
> 
> I ran some tests by manipulating the PHP file
> \`nextcloud/lib/public/AppFramework/Http/EmptyContentSecurityPolicy.php\`
> 
> and added "else" blocks to all the missing policies, like in this example ("if" block is standard, "else" was added by me): 
> \`\`\`
> if(!empty($this-\>allowedFrameAncestors)) {
> $policy .= 'frame-ancestors ' . implode(' ', $this-\>allowedFrameAncestors);
> $policy .= ';';
> }
> else {
> $policy .= "frame-ancestors 'self';";
> }
> \`\`\`
> 
> Due to this change, the site reports:
> 
> \----------
> \*\*Content-Security-Policy:\*\*	default-src 'none';base-uri 'none';manifest-src 'self';form-action 'self';script-src 'nonce-ZS-\[...\]-D0=';style-src 'self' 'unsafe-inline' 'unsafe-inline';img-src 'self' data: blob:;font-src 'self';connect-src 'self' ;media-src 'self' blob:; \*\*frame-src 'self' https://office.mydomain.tld https://www.draw.io;\*\* child-src 'self'; \*\*frame-ancestors 'self';worker-src 'self'\*\*
> 
> \-----------
> 
> I know it's a dirty hack right now, but I don't understand the code enough to correctly fix that. However, it works that way. I ran all NC14.0.x release with this or similar changes in that file without any issues or limitations.
> 
> \### Steps to reproduce
> 1. Run the test of https://observatory.mozilla.org against an NC15 server
> 2. look out for the raw Content-Security-Policy response
> 
> \### Expected behaviour
> All the policies appear in that CSP response
> 
> \### Actual behaviour
> These policies are missing completely, so the CSP is not as strict as probably intended. 
> 
> \### Server configuration
> 
> \*\*Operating system\*\*: ArchLinux 4.14.87-1-lts
> 
> \*\*Web server:\*\* nginx 1.14.2
> 
> \*\*Database:\*\* 10.1.37-MariaDB
> 
> \*\*PHP version:\*\* 7.2.13
> 
> \*\*Nextcloud version:\*\* NC 15.0.0.10
> 
> \*\*Updated from an older Nextcloud/ownCloud or fresh install:\*\* Updated via web updater from NC14.0.4
> 
> \*\*Where did you install Nextcloud from:\*\* NC internal web updater
> 
> \*\*Signing status:\*\*
> \<details\>
> \<summary\>Signing status\</summary\>
> 
> \`\`\`
> No errors have been found.
> \`\`\`
> \</details\>
> 
> \*\*List of activated apps:\*\*
> \<details\>
> \<summary\>App list\</summary\>
> 
> \`\`\`
> Enabled:
> - accessibility: 1.1.0
> - activity: 2.8.2
> - admin\_audit: 1.5.0
> - announcementcenter: 3.4.0
> - apporder: 0.6.0
> - audioplayer: 2.4.1
> - bookmarks: 0.14.3
> - bruteforcesettings: 1.2.0
> - calendar: 1.6.4
> - cloud\_federation\_api: 0.1.0
> - comments: 1.5.0
> - contacts: 2.1.8
> - dav: 1.8.0
> - deck: 0.5.1
> - dropit: 0.1.3
> - event\_update\_notification: 0.3.1
> - external: 3.2.0
> - federatedfilesharing: 1.5.0
> - federation: 1.5.0
> - files: 1.10.0
> - files\_accesscontrol: 1.5.0
> - files\_automatedtagging: 1.5.0
> - files\_downloadactivity: 1.4.0
> - files\_external: 1.6.0
> - files\_markdown: 2.0.5
> - files\_pdfviewer: 1.4.0
> - files\_retention: 1.4.0
> - files\_sharing: 1.7.0
> - files\_texteditor: 2.7.0
> - files\_trashbin: 1.5.0
> - files\_versions: 1.8.0
> - files\_videoplayer: 1.4.0
> - firstrunwizard: 2.4.0
> - gallery: 18.2.0
> - logreader: 2.0.0
> - lookup\_server\_connector: 1.3.0
> - mail: 0.11.0
> - metadata: 0.8.0
> - nextcloud\_announcements: 1.4.0
> - notes: 2.5.1
> - notifications: 2.3.0
> - oauth2: 1.3.0
> - ojsxc: 3.4.3
> - onlyoffice: 2.1.2
> - password\_policy: 1.5.0
> - previewgenerator: 2.0.0
> - provisioning\_api: 1.5.0
> - quota\_warning: 1.4.0
> - ransomware\_protection: 1.3.0
> - serverinfo: 1.5.0
> - sharebymail: 1.5.0
> - sharerenamer: 2.3.0
> - spreed: 4.99.0
> - support: 1.0.0
> - systemtags: 1.5.0
> - tasks: 0.9.8
> - telephoneprovider: 1.0.2
> - theming: 1.6.0
> - twofactor\_backupcodes: 1.4.1
> - twofactor\_totp: 2.1.0
> - updatenotification: 1.5.0
> - workflowengine: 1.5.0
> Disabled:
> - camerarawpreviews
> - checksum
> - circles
> - cms\_pico
> - dashboard
> - dicomviewer
> - drawio
> - encryption
> - files\_mindmap
> - files\_reader
> - files\_rightclick
> - issuetemplate
> - polls
> - ransomware\_detection
> - socialsharing\_email
> - survey\_client
> - user\_external
> - user\_ldap
> - user\_usage\_report
> \`\`\`
> \</details\>
> 
> \*\*Nextcloud configuration:\*\*
> \<details\>
> \<summary\>Config report\</summary\>
> 
> \`\`\`
> {
> "system": {
> "instanceid": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "passwordsalt": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "secret": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "trusted\_domains": \[
> "cloud.mydomain.tld",
> "192.168.1.100",
> "localhost"
> \],
> "datadirectory": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "dbtype": "mysql",
> "dbname": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "dbhost": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "dbport": "",
> "dbtableprefix": "oc\_",
> "dbuser": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "dbpassword": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "version": "15.0.0.10",
> "logtimezone": "Europe\\/Berlin",
> "appstore.experimental.enabled": true,
> "appstoreenabled": true,
> "appstoreurl": "https:\\/\\/api.nextcloud.com\\/v1",
> "appcodechecker": true,
> "apps\_paths": \[
> {
> "path": "\\/var\\/www\\/nextcloud\\/apps",
> "url": "\\/apps",
> "writable": true
> }
> \],
> "mail\_smtpmode": "smtp",
> "mail\_smtpauth": 1,
> "mail\_smtpport": "587",
> "mail\_smtphost": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "mail\_smtpauthtype": "LOGIN",
> "mail\_from\_address": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "mail\_domain": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "mail\_smtpsecure": "tls",
> "mail\_smtpname": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "mail\_smtppassword": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "preview\_libreoffice\_path": "\\/usr\\/bin\\/libreoffice",
> "enabledPreviewProviders": \[
> "OC\\\\Preview\\\\PNG",
> "OC\\\\Preview\\\\JPEG",
> "OC\\\\Preview\\\\GIF",
> "OC\\\\Preview\\\\BMP",
> "OC\\\\Preview\\\\XBitmap",
> "OC\\\\Preview\\\\MP3",
> "OC\\\\Preview\\\\TXT",
> "OC\\\\Preview\\\\MarkDown",
> "OC\\\\Preview\\\\TIFF",
> "OCA\\\\CameraRawPreviews\\\\RawPreview",
> "OCA\\\\CameraRawPreviews\\\\IndesignPreview",
> "OC\\\\Preview\\\\Movie",
> "OC\\\\Preview\\\\Photoshop"
> \],
> "filelocking.enabled": true,
> "memcache.local": "\\\\OC\\\\Memcache\\\\APCu",
> "memcache.locking": "\\\\OC\\\\Memcache\\\\Redis",
> "redis": {
> "host": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "port": 0,
> "timeout": 0,
> "password": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*"
> },
> "maintenance": false,
> "updater.server.url": "https:\\/\\/updates.nextcloud.com\\/updater\_server\\/",
> "updater.release.channel": "stable",
> "loglevel": 2,
> "theme": "",
> "installed": true,
> "overwrite.cli.url": "https:\\/\\/cloud.mydomain.tld",
> "defaultapp": "apporder",
> "updater.secret": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*"
> }
> }
> \`\`\`
> \</details\>
> 
> \*\*Are you using external storage, if yes which one:\*\* in OS mounted smb share via CIFS as additional external drive. All user data are on internal storage, however.
> 
> \*\*Are you using encryption:\*\* no
> 
> \*\*Are you using an external user-backend, if yes which one:\*\* no
> 
> \### Logs
> Not applicable as the server runs perfectly fine. There are no error messages that might be related.

With my configuration changes I reached a score of 120/100 🙂

> The current maximum possible score is 135 out of 100.

So 15 points still missing to the absolute maximum, but “unsafe-inline” for style-src policy is still lowering the score.  
I think I read somewhere, that style-src “unsafe-inline” comes from certain apps which haven’t been updated to the new NC directives. So this will be improved in the feature in any case.

---

<div class="post-metadata">

**Author:** ![rakekniven](https://help.nextcloud.com/user_avatar/help.nextcloud.com/rakekniven/32/67096_2.png) [@rakekniven](https://help.nextcloud.com/u/rakekniven)\
**Post date:** [December 26, 2018, 4:51pm UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/58 "2018-12-26T16:51:33Z")

</div>

Reached A+ at security headers as well with NC 15.

Did not change any code and got 110/100 at mozilla.

My result looks like this:

 ![18](https://help.nextcloud.com/uploads/default/original/2X/6/69d395ee877a7500d1f81ce4ff9b004decfe4061.png)

How about yours?

---

<div class="post-metadata">

**Author:** ![Schmu](https://help.nextcloud.com/user_avatar/help.nextcloud.com/schmu/32/7823_2.png) [@Schmu](https://help.nextcloud.com/u/Schmu)\
**Post date:** [December 26, 2018, 11:20pm UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/59 "2018-12-26T23:20:33Z")

</div>

It is 120/100 for me:

 ![grafik](https://help.nextcloud.com/uploads/default/original/2X/1/117666208df2f94c9b2fd9858eaffc42d655fbff.png)

---

<div class="post-metadata">

**Author:** ![Ark74](https://help.nextcloud.com/user_avatar/help.nextcloud.com/ark74/32/2071_2.png) [@Ark74](https://help.nextcloud.com/u/Ark74)\
**Post date:** [December 31, 2018, 6:04am UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/60 "2018-12-31T06:04:32Z")

</div>

My guess is that some apps may hit the score.

Im getting 110/100 with the exact same recommendations.

Maybe is the web server configuration.

---

<div class="post-metadata">

**Author:** ![Schmu](https://help.nextcloud.com/user_avatar/help.nextcloud.com/schmu/32/7823_2.png) [@Schmu](https://help.nextcloud.com/u/Schmu)\
**Post date:** [December 31, 2018, 8:24am UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/61 "2018-12-31T08:24:55Z")

</div>

> [@Ark74](#):
>
> Im getting 110/100 with the exact same recommendations.
> 
> Maybe is the web server configuration.

As mentioned, I made some changes to my configuration, in order to get a better score.

> [@Schmu](#):
>
> With my configuration changes I reached a score of 120/100 🙂

I changed the web server configuration and added an additional CSP header for “Feature Policy” in my nginx config:  
`add_header Feature-Policy "accelerometer 'none'; autoplay 'self'; geolocation 'none'; midi 'none'; notifications 'self'; push 'self'; sync-xhr 'self'; microphone 'self'; camera 'self'; magnetometer 'none'; gyroscope 'none'; speaker 'self'; vibrate 'self'; fullscreen 'self'; payment 'none'; usb 'none'";`

This change should be pretty safe and I believe this can be recommended. In case someone integrated other services and sites, which require some of these features, the configuration needs some adaption of course to allow ‘self’ and the other service/ site.

And in addition I changes one PHP file of Nextcloud to force the usage of the CSPs which are reported to be missing on the testing site: frame-ancestors and form-action.  
Strangely “frame-ancestors” is actually defined in the PHP code, but somehow it doesn’t end up in the header. I reported this as probable bug on Github already:

> <https://github.com/nextcloud/server/issues/13042>
>
> When scanning my NC server with:
> https://observatory.mozilla.org
> 
> I notice th…at a few (many?) CSPs are not set at all, although they can be found in the source code. 
> I noticed this phenomenon in NC14 already but thought, due to the planned rework of CSP with NC15, this might get "corrected" in this latest release. After a fresh upgrade to NC15 the above-mentioned site still reports some policies missing.
> 
> The output is:
> 
> \------------
> \*\*Content-Security-Policy:\*\*	default-src 'none';base-uri 'none';manifest-src 'self';script-src 'nonce-ZS \[...\] D0=';style-src 'self' 'unsafe-inline' 'unsafe-inline';img-src 'self' data: blob:;font-src 'self';connect-src 'self' ;media-src 'self' blob:;child-src 'self';
> 
> \-----------
> 
> The policies missing, although mentioned in the PHP file 
> \`nextcloud/lib/public/AppFramework/Http/EmptyContentSecurityPolicy.php\`:
> \- worker-src
> \- frame-ancestors
> \- frame-src
> 
> What could be added by this opportunity is:
> \- form-action
> 
> I ran some tests by manipulating the PHP file
> \`nextcloud/lib/public/AppFramework/Http/EmptyContentSecurityPolicy.php\`
> 
> and added "else" blocks to all the missing policies, like in this example ("if" block is standard, "else" was added by me): 
> \`\`\`
> if(!empty($this-\>allowedFrameAncestors)) {
> $policy .= 'frame-ancestors ' . implode(' ', $this-\>allowedFrameAncestors);
> $policy .= ';';
> }
> else {
> $policy .= "frame-ancestors 'self';";
> }
> \`\`\`
> 
> Due to this change, the site reports:
> 
> \----------
> \*\*Content-Security-Policy:\*\*	default-src 'none';base-uri 'none';manifest-src 'self';form-action 'self';script-src 'nonce-ZS-\[...\]-D0=';style-src 'self' 'unsafe-inline' 'unsafe-inline';img-src 'self' data: blob:;font-src 'self';connect-src 'self' ;media-src 'self' blob:; \*\*frame-src 'self' https://office.mydomain.tld https://www.draw.io;\*\* child-src 'self'; \*\*frame-ancestors 'self';worker-src 'self'\*\*
> 
> \-----------
> 
> I know it's a dirty hack right now, but I don't understand the code enough to correctly fix that. However, it works that way. I ran all NC14.0.x release with this or similar changes in that file without any issues or limitations.
> 
> \### Steps to reproduce
> 1. Run the test of https://observatory.mozilla.org against an NC15 server
> 2. look out for the raw Content-Security-Policy response
> 
> \### Expected behaviour
> All the policies appear in that CSP response
> 
> \### Actual behaviour
> These policies are missing completely, so the CSP is not as strict as probably intended. 
> 
> \### Server configuration
> 
> \*\*Operating system\*\*: ArchLinux 4.14.87-1-lts
> 
> \*\*Web server:\*\* nginx 1.14.2
> 
> \*\*Database:\*\* 10.1.37-MariaDB
> 
> \*\*PHP version:\*\* 7.2.13
> 
> \*\*Nextcloud version:\*\* NC 15.0.0.10
> 
> \*\*Updated from an older Nextcloud/ownCloud or fresh install:\*\* Updated via web updater from NC14.0.4
> 
> \*\*Where did you install Nextcloud from:\*\* NC internal web updater
> 
> \*\*Signing status:\*\*
> \<details\>
> \<summary\>Signing status\</summary\>
> 
> \`\`\`
> No errors have been found.
> \`\`\`
> \</details\>
> 
> \*\*List of activated apps:\*\*
> \<details\>
> \<summary\>App list\</summary\>
> 
> \`\`\`
> Enabled:
> - accessibility: 1.1.0
> - activity: 2.8.2
> - admin\_audit: 1.5.0
> - announcementcenter: 3.4.0
> - apporder: 0.6.0
> - audioplayer: 2.4.1
> - bookmarks: 0.14.3
> - bruteforcesettings: 1.2.0
> - calendar: 1.6.4
> - cloud\_federation\_api: 0.1.0
> - comments: 1.5.0
> - contacts: 2.1.8
> - dav: 1.8.0
> - deck: 0.5.1
> - dropit: 0.1.3
> - event\_update\_notification: 0.3.1
> - external: 3.2.0
> - federatedfilesharing: 1.5.0
> - federation: 1.5.0
> - files: 1.10.0
> - files\_accesscontrol: 1.5.0
> - files\_automatedtagging: 1.5.0
> - files\_downloadactivity: 1.4.0
> - files\_external: 1.6.0
> - files\_markdown: 2.0.5
> - files\_pdfviewer: 1.4.0
> - files\_retention: 1.4.0
> - files\_sharing: 1.7.0
> - files\_texteditor: 2.7.0
> - files\_trashbin: 1.5.0
> - files\_versions: 1.8.0
> - files\_videoplayer: 1.4.0
> - firstrunwizard: 2.4.0
> - gallery: 18.2.0
> - logreader: 2.0.0
> - lookup\_server\_connector: 1.3.0
> - mail: 0.11.0
> - metadata: 0.8.0
> - nextcloud\_announcements: 1.4.0
> - notes: 2.5.1
> - notifications: 2.3.0
> - oauth2: 1.3.0
> - ojsxc: 3.4.3
> - onlyoffice: 2.1.2
> - password\_policy: 1.5.0
> - previewgenerator: 2.0.0
> - provisioning\_api: 1.5.0
> - quota\_warning: 1.4.0
> - ransomware\_protection: 1.3.0
> - serverinfo: 1.5.0
> - sharebymail: 1.5.0
> - sharerenamer: 2.3.0
> - spreed: 4.99.0
> - support: 1.0.0
> - systemtags: 1.5.0
> - tasks: 0.9.8
> - telephoneprovider: 1.0.2
> - theming: 1.6.0
> - twofactor\_backupcodes: 1.4.1
> - twofactor\_totp: 2.1.0
> - updatenotification: 1.5.0
> - workflowengine: 1.5.0
> Disabled:
> - camerarawpreviews
> - checksum
> - circles
> - cms\_pico
> - dashboard
> - dicomviewer
> - drawio
> - encryption
> - files\_mindmap
> - files\_reader
> - files\_rightclick
> - issuetemplate
> - polls
> - ransomware\_detection
> - socialsharing\_email
> - survey\_client
> - user\_external
> - user\_ldap
> - user\_usage\_report
> \`\`\`
> \</details\>
> 
> \*\*Nextcloud configuration:\*\*
> \<details\>
> \<summary\>Config report\</summary\>
> 
> \`\`\`
> {
> "system": {
> "instanceid": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "passwordsalt": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "secret": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "trusted\_domains": \[
> "cloud.mydomain.tld",
> "192.168.1.100",
> "localhost"
> \],
> "datadirectory": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "dbtype": "mysql",
> "dbname": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "dbhost": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "dbport": "",
> "dbtableprefix": "oc\_",
> "dbuser": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "dbpassword": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "version": "15.0.0.10",
> "logtimezone": "Europe\\/Berlin",
> "appstore.experimental.enabled": true,
> "appstoreenabled": true,
> "appstoreurl": "https:\\/\\/api.nextcloud.com\\/v1",
> "appcodechecker": true,
> "apps\_paths": \[
> {
> "path": "\\/var\\/www\\/nextcloud\\/apps",
> "url": "\\/apps",
> "writable": true
> }
> \],
> "mail\_smtpmode": "smtp",
> "mail\_smtpauth": 1,
> "mail\_smtpport": "587",
> "mail\_smtphost": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "mail\_smtpauthtype": "LOGIN",
> "mail\_from\_address": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "mail\_domain": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "mail\_smtpsecure": "tls",
> "mail\_smtpname": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "mail\_smtppassword": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "preview\_libreoffice\_path": "\\/usr\\/bin\\/libreoffice",
> "enabledPreviewProviders": \[
> "OC\\\\Preview\\\\PNG",
> "OC\\\\Preview\\\\JPEG",
> "OC\\\\Preview\\\\GIF",
> "OC\\\\Preview\\\\BMP",
> "OC\\\\Preview\\\\XBitmap",
> "OC\\\\Preview\\\\MP3",
> "OC\\\\Preview\\\\TXT",
> "OC\\\\Preview\\\\MarkDown",
> "OC\\\\Preview\\\\TIFF",
> "OCA\\\\CameraRawPreviews\\\\RawPreview",
> "OCA\\\\CameraRawPreviews\\\\IndesignPreview",
> "OC\\\\Preview\\\\Movie",
> "OC\\\\Preview\\\\Photoshop"
> \],
> "filelocking.enabled": true,
> "memcache.local": "\\\\OC\\\\Memcache\\\\APCu",
> "memcache.locking": "\\\\OC\\\\Memcache\\\\Redis",
> "redis": {
> "host": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*",
> "port": 0,
> "timeout": 0,
> "password": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*"
> },
> "maintenance": false,
> "updater.server.url": "https:\\/\\/updates.nextcloud.com\\/updater\_server\\/",
> "updater.release.channel": "stable",
> "loglevel": 2,
> "theme": "",
> "installed": true,
> "overwrite.cli.url": "https:\\/\\/cloud.mydomain.tld",
> "defaultapp": "apporder",
> "updater.secret": "\*\*\*REMOVED SENSITIVE VALUE\*\*\*"
> }
> }
> \`\`\`
> \</details\>
> 
> \*\*Are you using external storage, if yes which one:\*\* in OS mounted smb share via CIFS as additional external drive. All user data are on internal storage, however.
> 
> \*\*Are you using encryption:\*\* no
> 
> \*\*Are you using an external user-backend, if yes which one:\*\* no
> 
> \### Logs
> Not applicable as the server runs perfectly fine. There are no error messages that might be related.

So just to have a complete explanation what I did, here it is, but use with caution and be aware that it might cause some apps to stop working (haven’t discovered any so far).

So in /var/www/nextcloud/lib/public/AppFramework/Http/EmptyContentSecurityPolicy.php I added a new line for the policy for “form-action” here:

```auto
public function buildPolicy() {
                $policy = "default-src 'none';";
                $policy .= "base-uri 'none';";
                $policy .= "manifest-src 'self';";
                $policy .= "form-action 'self';";

```

Farther down below I added a few “else” blocks:

```auto
                if(!empty($this->allowedFrameDomains)) {
                        $policy .= 'frame-src ' . implode(' ', $this->allowedFrameDomains);
                        $policy .= ';';
                }
                else {
                        $policy .= "frame-src 'self' https://office.mydomain.tld https://www.draw.io;";
                }

                if(!empty($this->allowedChildSrcDomains)) {
                        $policy .= 'child-src ' . implode(' ', $this->allowedChildSrcDomains);
                        $policy .= ';';
                }

                if(!empty($this->allowedFrameAncestors)) {
                        $policy .= 'frame-ancestors ' . implode(' ', $this->allowedFrameAncestors);
                        $policy .= ';';
                }
                else {
                        $policy .= "frame-ancestors 'self';";
                }

                if (!empty($this->allowedWorkerSrcDomains)) {
                        $policy .= 'worker-src ' . implode(' ', $this->allowedWorkerSrcDomains);
                        $policy .= ';';
                }
                else {
                        $policy .= "worker-src 'self';";
                }

```

This works for me to improve my CSP headers, but I wouldn’t recommend this changes to everybody. The else blocks are rather dirty hacks, because I don’t know exactly where and why the headers are not added to the policy.  
I hope this explains it enough now 🙂

---

<div class="post-metadata">

**Author:** ![RuudschMaHinda](https://help.nextcloud.com/user_avatar/help.nextcloud.com/ruudschmahinda/32/79_2.png) [@RuudschMaHinda](https://help.nextcloud.com/u/RuudschMaHinda)\
**Post date:** [April 26, 2019, 5:22am UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/62 "2019-04-26T05:22:19Z")

</div>

Currently nextcloud is setting this policy itself.

Even though the documentation says to set it in your server configuration, doing that sends that policy twice and therefor produces this error.

According to this github bug request it is currently advised to comment out that bit in your server configuration / .htaccess (when using apache)

> <https://github.com/nextcloud/server/issues/8207>

---

<div class="post-metadata">

**Author:** ![Felix\_Haupts](https://help.nextcloud.com/user_avatar/help.nextcloud.com/felix_haupts/32/11251_2.png) [@Felix\_Haupts](https://help.nextcloud.com/u/Felix_Haupts)\
**Post date:** [January 8, 2020, 10:10am UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/63 "2020-01-08T10:10:57Z")

</div>

Thanks martva, your post helped me. I experienced the same issue when updating to NC 17 (hence my decission to reanimate the thread). It was also caused due to the fact, that the header-policy was set twice: in my nextcloud-ssl.conf and the .htaccess I decided to delete the lines in my config in /etc/apache2/sites-available since I understand that the options in .htaccess are added by nextcloud and can be changed with any new update. I think this way it is more unlikely to get the same issue with the next update.

---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [December 4, 2024, 7:41am UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/64 "2024-12-04T07:41:32Z")

</div>



---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [December 9, 2024, 3:16pm UTC](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613/65 "2024-12-09T15:16:51Z")

</div>



[Previous page](https://help.nextcloud.com/t/the-referrer-policy-http-header-is-not-set-to-no-referrer/36613.md?page=2)
