comparison modules/website/files/zzz-0-custom.conf @ 174:1457b5365c79 puppet-3.6

Add extra headers for improved security practice
author IBBoard <dev@ibboard.co.uk>
date Sat, 03 Mar 2018 14:20:06 +0000
parents 3c4f495d4eac
children 1b93429d28b8
comparison
equal deleted inserted replaced
173:c72d2b5f9be2 174:1457b5365c79
86 Require all denied 86 Require all denied
87 </LimitExcept> 87 </LimitExcept>
88 </Location> 88 </Location>
89 89
90 ServerTokens Minor 90 ServerTokens Minor
91
92 Header always set Referrer-Policy "no-referrer-when-downgrade"
93 Header always set Expect-CT "max-age=0, report-uri='https://ibboard.report-uri.io/r/default/ct/reportOnly'"
94 Header always set Content-Security-Policy "upgrade-insecure-requests"
95 Header always set Content-Security-Policy-Report-Only "default-src 'none'; img-src 'self'; script-src 'self'; style-src 'self'"
96 #; report-uri https://ibboard.report-uri.com/r/d/csp/reportOnly"