nginx-config

Handy nginx configurations
Log | Files | Refs

security_headers (616B)


      1 add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
      2 add_header X-Content-Type-Options "nosniff" always;
      3 add_header X-Frame-Options "DENY" always;
      4 add_header Referrer-Policy "no-referrer" always;
      5 
      6 add_header Content-Security-Policy "frame-ancestors 'self' https://*.example.com" always;
      7 add_header Content-Security-Policy "default-src 'self'; img-src 'self' https:; media-src 'self' https:; frame-ancestors 'none';" always;
      8 
      9 #add_header Referrer-Policy "strict-origin-when-cross-origin" always;
     10 #add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;