6 lines
		
	
	
		
			320 B
		
	
	
	
		
			ApacheConf
		
	
	
	
	
	
			
		
		
	
	
			6 lines
		
	
	
		
			320 B
		
	
	
	
		
			ApacheConf
		
	
	
	
	
	
Header set Content-Security-Policy "default-src *; script-src 'self' ajax.googleapis.com; style-src 'self'"
 | 
						|
Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
 | 
						|
Header set X-Frame-Options "sameorigin"
 | 
						|
Header set X-XSS-Protection "1; mode=block"
 | 
						|
Header set X-Content-Type-Options "nosniff"
 |