Use sameorigin as frame policy in CSP header.

This commit is contained in:
daniel 2016-09-10 09:41:03 +02:00
parent 5722c96947
commit 16f3c03f15

View File

@ -1,5 +1,5 @@
Header set Content-Security-Policy "default-src *; script-src 'self' ajax.googleapis.com; style-src 'self'" Header set Content-Security-Policy "default-src *; script-src 'self' ajax.googleapis.com; style-src 'self'"
Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
Header set X-Frame-Options "deny" Header set X-Frame-Options "sameorigin"
Header set X-XSS-Protection "1; mode=block" Header set X-XSS-Protection "1; mode=block"
Header set X-Content-Type-Options "nosniff" Header set X-Content-Type-Options "nosniff"