summaryrefslogtreecommitdiff
path: root/roles/nginx/base/files/snippets/security-headers.conf
blob: b94d479d8d1ecc7e16c119c148e082db0cdb16a1 (plain) (blame)
1
2
3
4
add_header X-Frame-Options DENY;
add_header X-Content-Type-Options nosniff;
add_header X-XSS-Protection "1; mode=block";
# add_header Content-Security-Policy "default-src 'none'; connect-src 'self'; img-src 'self'; script-src 'self'; style-src 'self'";