File tree Expand file tree Collapse file tree 2 files changed +14
-14
lines changed
admin_manual/installation Expand file tree Collapse file tree 2 files changed +14
-14
lines changed Original file line number Diff line number Diff line change @@ -69,13 +69,13 @@ server {
69
69
client_body_buffer_size 512k;
70
70
71
71
# HTTP response headers borrowed from Nextcloud `.htaccess`
72
- add_header Referrer-Policy "no-referrer" always;
73
- add_header X-Content-Type-Options "nosniff" always;
74
- add_header X-Download-Options "noopen" always;
75
- add_header X-Frame-Options "SAMEORIGIN" always;
76
- add_header X-Permitted-Cross-Domain-Policies "none" always;
77
- add_header X-Robots-Tag "none" always;
78
- add_header X-XSS-Protection "0" always;
72
+ add_header Referrer-Policy "no-referrer" always;
73
+ add_header X-Content-Type-Options "nosniff" always;
74
+ add_header X-Download-Options "noopen" always;
75
+ add_header Content-Security-Policy "default-src 'self'" always;
76
+ add_header X-Permitted-Cross-Domain-Policies "none" always;
77
+ add_header X-Robots-Tag "none" always;
78
+ add_header X-XSS-Protection "0" always;
79
79
80
80
# Remove X-Powered-By, which is an information leak
81
81
fastcgi_hide_header X-Powered-By;
Original file line number Diff line number Diff line change @@ -92,13 +92,13 @@ server {
92
92
client_body_buffer_size 512k;
93
93
94
94
# HTTP response headers borrowed from Nextcloud `.htaccess`
95
- add_header Referrer-Policy "no-referrer" always;
96
- add_header X-Content-Type-Options "nosniff" always;
97
- add_header X-Download-Options "noopen" always;
98
- add_header X-Frame-Options "SAMEORIGIN" always;
99
- add_header X-Permitted-Cross-Domain-Policies "none" always;
100
- add_header X-Robots-Tag "none" always;
101
- add_header X-XSS-Protection "1; mode=block" always;
95
+ add_header Referrer-Policy "no-referrer" always;
96
+ add_header X-Content-Type-Options "nosniff" always;
97
+ add_header X-Download-Options "noopen" always;
98
+ add_header Content-Security-Policy "default-src 'self'" always;
99
+ add_header X-Permitted-Cross-Domain-Policies "none" always;
100
+ add_header X-Robots-Tag "none" always;
101
+ add_header X-XSS-Protection "0" always;
102
102
103
103
# Remove X-Powered-By, which is an information leak
104
104
fastcgi_hide_header X-Powered-By;
You can’t perform that action at this time.
0 commit comments