Ammend CSP (#1138)

This commit is contained in:
Xavier Guimard 2017-01-21 09:24:29 +00:00
parent 93e02e1400
commit 3b3941a620
4 changed files with 4 additions and 4 deletions

View File

@ -41,7 +41,7 @@
SetHandler fcgid-script
Options +ExecCGI
<IfModule mod_headers.c>
header set Content-Security-Policy "default-src 'self';"
header set Content-Security-Policy "default-src 'self';frame-ancessor 'none':form-action 'self';"
header set X-Content-Type-Options nosniff
header set X-Frame-Options DENY
header set X-XSS-Protection "1; mode=block"

View File

@ -41,7 +41,7 @@
SetHandler fcgid-script
Options +ExecCGI
<IfModule mod_headers.c>
header set Content-Security-Policy "default-src 'self';"
header set Content-Security-Policy "default-src 'self';frame-ancessor 'none':form-action 'self';"
header set X-Content-Type-Options nosniff
header set X-Frame-Options DENY
header set X-XSS-Protection "1; mode=block"

View File

@ -41,7 +41,7 @@
SetHandler fcgid-script
Options +ExecCGI
<IfModule mod_headers.c>
header set Content-Security-Policy "default-src 'self';"
header set Content-Security-Policy "default-src 'self';frame-ancessor 'none':form-action 'self';"
header set X-Content-Type-Options nosniff
header set X-Frame-Options DENY
header set X-XSS-Protection "1; mode=block"

View File

@ -16,7 +16,7 @@ server {
fastcgi_param PATH_INFO $fastcgi_path_info;
add_header X-Content-Type-Options nosniff;
add_header X-XSS-Protection "1; mode=block";
add_header Content-Security-Policy "default-src 'self';";
add_header Content-Security-Policy "default-src 'self';frame-ancessor 'none':form-action 'self';";
add_header X-Frame-Options DENY;
# Uncomment this if you use https only
#add_header Strict-Transport-Security "15768000";