2016-09-10 07:46:58 +00:00
|
|
|
Header set Content-Security-Policy "default-src *; script-src 'self' ajax.googleapis.com code.jquery.com; style-src 'self'"
|
2016-08-28 10:14:04 +00:00
|
|
|
Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
|
2016-09-10 07:44:36 +00:00
|
|
|
# Header set X-Frame-Options "sameorigin"
|
2016-08-28 10:14:04 +00:00
|
|
|
Header set X-XSS-Protection "1; mode=block"
|
|
|
|
Header set X-Content-Type-Options "nosniff"
|