Use sameorigin as frame policy in CSP header.
This commit is contained in:
parent
5722c96947
commit
16f3c03f15
@ -1,5 +1,5 @@
|
|||||||
Header set Content-Security-Policy "default-src *; script-src 'self' ajax.googleapis.com; style-src 'self'"
|
Header set Content-Security-Policy "default-src *; script-src 'self' ajax.googleapis.com; style-src 'self'"
|
||||||
Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
|
Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
|
||||||
Header set X-Frame-Options "deny"
|
Header set X-Frame-Options "sameorigin"
|
||||||
Header set X-XSS-Protection "1; mode=block"
|
Header set X-XSS-Protection "1; mode=block"
|
||||||
Header set X-Content-Type-Options "nosniff"
|
Header set X-Content-Type-Options "nosniff"
|
||||||
|
Loading…
Reference in New Issue
Block a user