Privacy
Permissions-Policy
Turn off powerful features you don't use.
What it is
Declares which browser features (camera, microphone, geolocation, payment, USB…) the page and its iframes may use.
Why it matters
Reduces the blast radius of an XSS or a malicious third-party embed by denying access to sensitive device APIs.
Risk without it
Without it, injected or embedded code can prompt for or access powerful features under your origin.
Recommended
Deny everything you don't use, e.g. camera=(), microphone=(), geolocation=(), payment=(), usb=().
Set it
add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=(), interest-cohort=()" always;