security-headers.conf 703 B

123456789101112
  1. # Nginx UI Template Start
  2. name = "Nginx Security Headers"
  3. author = "@sanvu88"
  4. description = { en = "Nginx Security Headers Config", zh_CN = "Nginx Headers 安全配置", vi_VN = "Cấu hình Headers tăng cường bảo mật"}
  5. # Nginx UI Template End
  6. add_header X-XSS-Protection "1; mode=block" always;
  7. add_header X-Content-Type-Options "nosniff" always;
  8. add_header Referrer-Policy "no-referrer-when-downgrade" always;
  9. add_header Content-Security-Policy "default-src 'self' http: https: ws: wss: data: blob: 'unsafe-inline'; frame-ancestors 'self';" always;
  10. add_header Permissions-Policy "interest-cohort=()" always;
  11. add_header X-Frame-Options "SAMEORIGIN";