Create hsts.conf
This commit is contained in:
parent
562cc5e8c3
commit
91812b185a
|
@ -0,0 +1,8 @@
|
|||
# Warning : this line enable HSTS for your domain and all subdomains (ngx_http_headers_module is required) (31536000 seconds = 12 months)
|
||||
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload";
|
||||
|
||||
# Extra security headers
|
||||
add_header X-Frame-Options SAMEORIGIN;
|
||||
add_header X-Content-Type-Options nosniff;
|
||||
add_header X-XSS-Protection "1; mode=block";
|
||||
add_header Referrer-Policy "strict-origin-when-cross-origin";
|
Loading…
Reference in New Issue