From ef6a1cbd75aa1cb89ccab9f3d28172fc19406fae Mon Sep 17 00:00:00 2001 From: Jonas Smedegaard Date: Sun, 18 Oct 2020 22:16:03 +0200 Subject: add snippet local-securityheaders --- apache2/conf-available/local-securityheaders.conf | 25 +++++++++++++++++++++++ 1 file changed, 25 insertions(+) create mode 100644 apache2/conf-available/local-securityheaders.conf diff --git a/apache2/conf-available/local-securityheaders.conf b/apache2/conf-available/local-securityheaders.conf new file mode 100644 index 0000000..a72a25e --- /dev/null +++ b/apache2/conf-available/local-securityheaders.conf @@ -0,0 +1,25 @@ +# Security headers +# More info: + +# Avoid Clickjack attacks +Header always set X-Frame-Options "SAMEORIGIN" + +# Enable reflective XSS protection and block response when detecting an attack +Header always set X-Xss-Protection "1; mode=block" + +# Use strict MIME types +Header always set X-Content-Type-Options "nosniff" + +# Do not send the referrer header when navigating from HTTPS to HTTP, +# but always send the full URL when navigating from HTTP to any origin. +# More info: +Header set Referrer-Policy "no-referrer-when-downgrade" + +# Allow images, scripts, AJAX, form actions, and CSS from the same origin, +# and disallow any other resources to load (eg object, frame, media, etc). +# More info: +Header set Content-Security-Policy "default-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self'; base-uri 'self'; form-action 'self';" + +# More info: +# feature list: +Header set Permissions-Policy "accelerometer(self), ambient-light-sensor(self), autoplay(self), battery(self), camera(self), cross-origin-isolated(self), display-capture(self), document-domain(self), encrypted-media(self), execution-while-not-rendered(self), execution-while-out-of-viewport(self), fullscreen(self), geolocation(self), gyroscope(self), magnetometer(self), microphone(self), midi(self), navigation-override(self), payment(self), picture-in-picture(self), publickey-credentials-get(self), screen-wake-lock(self), sync-xhr(self), usb(self), web-share(self), xr-spatial-tracking(self)" -- cgit v1.2.3