headers by 0x6a03448f4d
← All headers
Privacy

Permissions-Policy

Turn off powerful features you don't use.

What it is

Declares which browser features (camera, microphone, geolocation, payment, USB…) the page and its iframes may use.

Why it matters

Reduces the blast radius of an XSS or a malicious third-party embed by denying access to sensitive device APIs.

Risk without it

Without it, injected or embedded code can prompt for or access powerful features under your origin.

Recommended

Deny everything you don't use, e.g. camera=(), microphone=(), geolocation=(), payment=(), usb=().

Set it

add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=(), interest-cohort=()" always;

References