diff --git a/conf/nginx.conf b/conf/nginx.conf index 0a08439e..9b6dfa63 100644 --- a/conf/nginx.conf +++ b/conf/nginx.conf @@ -43,5 +43,8 @@ server { ssl_certificate $SSL_CERTIFICATE; ssl_certificate_key $SSL_KEY; + # Add protection against clickjacking attacks by adding an X-Frame-Options + add_header X-Frame-Options "SAMEORIGIN"; + # ADDITIONAL DIRECTIVES HERE }