Skip to content

Commit 05c3010

Browse files
committed
re-apply #1714 add Content-Security-Policy header
1 parent 5a15443 commit 05c3010

File tree

2 files changed

+14
-14
lines changed

2 files changed

+14
-14
lines changed

admin_manual/installation/nginx-root.conf.sample

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -69,13 +69,13 @@ server {
6969
client_body_buffer_size 512k;
7070

7171
# HTTP response headers borrowed from Nextcloud `.htaccess`
72-
add_header Referrer-Policy "no-referrer" always;
73-
add_header X-Content-Type-Options "nosniff" always;
74-
add_header X-Download-Options "noopen" always;
75-
add_header X-Frame-Options "SAMEORIGIN" always;
76-
add_header X-Permitted-Cross-Domain-Policies "none" always;
77-
add_header X-Robots-Tag "none" always;
78-
add_header X-XSS-Protection "0" always;
72+
add_header Referrer-Policy "no-referrer" always;
73+
add_header X-Content-Type-Options "nosniff" always;
74+
add_header X-Download-Options "noopen" always;
75+
add_header Content-Security-Policy "default-src 'self'" always;
76+
add_header X-Permitted-Cross-Domain-Policies "none" always;
77+
add_header X-Robots-Tag "none" always;
78+
add_header X-XSS-Protection "0" always;
7979

8080
# Remove X-Powered-By, which is an information leak
8181
fastcgi_hide_header X-Powered-By;

admin_manual/installation/nginx-subdir.conf.sample

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -92,13 +92,13 @@ server {
9292
client_body_buffer_size 512k;
9393

9494
# HTTP response headers borrowed from Nextcloud `.htaccess`
95-
add_header Referrer-Policy "no-referrer" always;
96-
add_header X-Content-Type-Options "nosniff" always;
97-
add_header X-Download-Options "noopen" always;
98-
add_header X-Frame-Options "SAMEORIGIN" always;
99-
add_header X-Permitted-Cross-Domain-Policies "none" always;
100-
add_header X-Robots-Tag "none" always;
101-
add_header X-XSS-Protection "1; mode=block" always;
95+
add_header Referrer-Policy "no-referrer" always;
96+
add_header X-Content-Type-Options "nosniff" always;
97+
add_header X-Download-Options "noopen" always;
98+
add_header Content-Security-Policy "default-src 'self'" always;
99+
add_header X-Permitted-Cross-Domain-Policies "none" always;
100+
add_header X-Robots-Tag "none" always;
101+
add_header X-XSS-Protection "0" always;
102102

103103
# Remove X-Powered-By, which is an information leak
104104
fastcgi_hide_header X-Powered-By;

0 commit comments

Comments
 (0)