CSP on photos.afpy.org

This commit is contained in:
Julien Palard 2023-03-05 16:53:55 +01:00
parent 4163e91032
commit d4c74a252c
Signed by: mdk
GPG Key ID: 0EFC1AC1006886F8
1 changed files with 2 additions and 0 deletions

View File

@ -273,6 +273,8 @@
{
listen [::]:443 ssl http2; listen 443 ssl http2;
server_name photos.afpy.org;
add_header Content-Security-Policy "default-src 'none'; img-src 'self'; style-src 'self'; script-src 'self'; frame-ancestors 'self'";
add_header X-Content-Type-Options "nosniff";
include snippets/letsencrypt-photos.afpy.org.conf;
root /var/www/photos.afpy.org/;
}