Set frame-ancestors in Content-Security-Policy

https://infosec.mozilla.org/guidelines/web_security#x-frame-options
This commit is contained in:
Eric Nemchik 2020-10-29 10:13:55 -05:00 committed by GitHub
parent 50371fea4f
commit 01dd12f567
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -40,7 +40,7 @@ ssl_early_data on;
# Optional additional headers
#add_header Cache-Control "no-transform" always;
#add_header Content-Security-Policy "upgrade-insecure-requests";
#add_header Content-Security-Policy "upgrade-insecure-requests; frame-ancestors 'self'";
#add_header Referrer-Policy "same-origin" always;
#add_header X-Content-Type-Options "nosniff" always;
#add_header X-Frame-Options "SAMEORIGIN" always;