Add some common security headers for all sites

This commit is contained in:
Marko Korhonen 2023-04-04 01:00:48 +03:00
parent 3b1dcf4709
commit acc7aa6848

View file

@ -5,7 +5,11 @@ korhonen.cc, *.korhonen.cc {
}
header {
Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
X-Frame-Options DENY
X-XSS-Protection 0
X-Content-Type-Options nosniff
Referrer-Policy strict-origin-when-cross-origin
}
@homepage host korhonen.cc