new security headers, recommended by ZAP scan #29

This commit is contained in:
El RIDO 2021-04-05 18:21:55 +02:00
parent a86fc49145
commit 7b367cad23
No known key found for this signature in database
GPG key ID: 0F5C940A6BD81F92

View file

@ -5,6 +5,14 @@ server {
root /var/www;
index index.php index.html index.htm;
add_header Cross-Origin-Embedder-Policy require-corp;
add_header Cross-Origin-Resource-Policy same-origin;
add_header Cross-Origin-Opener-Policy same-origin;
add_header Referrer-Policy no-referrer;
add_header X-Content-Type-Options nosniff;
add_header X-Frame-Options deny;
add_header X-XSS-Protection "1; mode=block";
location / {
include /etc/nginx/location.d/*.conf;
try_files $uri $uri/ /index.php$is_args$args;