mirror of
https://github.com/mail-in-a-box/mailinabox.git
synced 2026-03-18 18:07:22 +01:00
add nginx security headers
This commit is contained in:
5
conf/nginx/security.conf
Normal file
5
conf/nginx/security.conf
Normal file
@@ -0,0 +1,5 @@
|
||||
add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload';
|
||||
add_header X-Frame-Options "SAMEORIGIN";
|
||||
add_header X-Content-Type-Options nosniff;
|
||||
add_header Content-Security-Policy-Report-Only "default-src 'self'; font-src *;img-src * data:; script-src *; style-src *;frame-ancestors 'self'";
|
||||
add_header Referrer-Policy "strict-origin";
|
||||
Reference in New Issue
Block a user