Skip to content

Commit

Permalink
added no referrer header and cleaned up other files
Browse files Browse the repository at this point in the history
  • Loading branch information
metaclassing committed Apr 3, 2018
1 parent f0d19b9 commit e267768
Show file tree
Hide file tree
Showing 8 changed files with 26 additions and 18 deletions.
15 changes: 0 additions & 15 deletions include/apicontentsecurity.conf

This file was deleted.

2 changes: 0 additions & 2 deletions include/hsts.conf

This file was deleted.

1 change: 1 addition & 0 deletions include/security/acao-star.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
add_header Access-Control-Allow-Origin '*' always;
13 changes: 13 additions & 0 deletions include/security/apicontentsecurity.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
# Content-Security-Policy
# default-src 'self';
# connect-src * data: blob: filesystem:;
# style-src 'self' data: chrome-extension-resource: 'unsafe-inline';
# img-src 'self' data: chrome-extension-resource:;
# frame-src 'self' data: chrome-extension-resource:;
# font-src 'self' data: chrome-extension-resource:;
# media-src * data: blob: filesystem:;
add_header Content-Security-Policy 'default-src self * unsafe-inline ; script-src * self unsafe-inline ; upgrade-insecure-requests;' always;

add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-XSS-Protection "1; mode=block" always;
5 changes: 5 additions & 0 deletions include/security/expectct.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# Expect-CT: report-uri="<uri>";
# enforce;
# max-age=<age>

add_header Expect-CT 'max-age=0; report-uri="https://1337.report-uri.com/r/d/ct/enforce"' always;
2 changes: 1 addition & 1 deletion include/hpkp.conf → include/security/hpkp.conf
Original file line number Diff line number Diff line change
Expand Up @@ -16,4 +16,4 @@
# max-age=15552000; includeSubDomains; report-uri="https://secureobscure.report-uri.io/r/default/hpkp/enforce"';

# Compressed into one line:
add_header Public-Key-Pins 'pin-sha256="YLh1dUR9y6Kja30RrAn7JKnbQG/uEtLMkBgFF2Fuihg="; pin-sha256="58qRu/uxh4gFezqAcERupSkRYBlBAvfcw7mEjGPLnNU="; max-age=15552000; includeSubDomains;"' always;
add_header Public-Key-Pins 'pin-sha256="YLh1dUR9y6Kja30RrAn7JKnbQG/uEtLMkBgFF2Fuihg="; pin-sha256="58qRu/uxh4gFezqAcERupSkRYBlBAvfcw7mEjGPLnNU="; max-age=15552000; includeSubDomains; report-uri="https://1337.report-uri.com/r/d/hpkp/enforce"' always;
5 changes: 5 additions & 0 deletions include/security/hsts.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# Strict-Transport-Security: max-age=<expire-time>
# Strict-Transport-Security: max-age=<expire-time>; includeSubDomains
# Strict-Transport-Security: max-age=<expire-time>; preload

add_header Strict-Transport-Security 'max-age=15552000; includeSubDomains; preload' always;
1 change: 1 addition & 0 deletions include/security/no-referer.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
add_header Referrer-Policy 'no-referrer' always;

0 comments on commit e267768

Please sign in to comment.