Isolation
Cross-Origin-Resource-Policy (CORP)
Control who can embed your resources.
What it is
Tells the browser which origins are allowed to load a given resource (script, image, JSON…).
Why it matters
Mitigates cross-site leaks (Spectre-style side channels and resource probing) by refusing cross-origin embedding.
Risk without it
Without CORP, other sites can embed and time your resources to infer information.
Recommended
same-origin for private resources; cross-origin for assets meant to be public.
Set it
add_header Cross-Origin-Resource-Policy "same-origin" always;