From 5c1c80668b1b0bdf045c161e1d66212c0c15d8a0 Mon Sep 17 00:00:00 2001 From: Marc Beninca Date: Tue, 6 Aug 2019 23:13:29 +0200 Subject: [PATCH] server/nginx/csp,sts --- in/personal/server/index.rst | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/in/personal/server/index.rst b/in/personal/server/index.rst index 3b0e2f7..c694798 100644 --- a/in/personal/server/index.rst +++ b/in/personal/server/index.rst @@ -388,7 +388,8 @@ Security listen 443 ssl http2; listen [::]:443 ssl http2; - add_header Strict-Transport-Security "max-age=31557600; includeSubDomains; preload"; + add_header Content-Security-Policy "default-src 'self'"; + add_header Strict-Transport-Security "max-age=31557600; includeSubDomains; preload" always; Sites ^^^^^