Headers HTTP Seguros en Apache

preview_player
Показать описание

sudo a2enmod headers

sudo apachectl -M

Header always set X-Xss-Protection "1; mode=block"
Header always set X-Content-Type-Options: nosniff
Header always set X-Frame-Options "SAMEORIGIN"
Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
Header always set Content-Security-Policy "default-src 'self'; font-src *;img-src * data:; script-src *; style-src *;"
Header always set Referrer-Policy "strict-origin"
Header always set Permissions-Policy "geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()"

Header edit Set-Cookie ^(.*)$ $1;HttpOnly;Secure
sudo systemctl restart apache2
Рекомендации по теме
Комментарии
Автор

Muchas gracias, eso es lo que necesitaba.

teodorglisic