-
-
Save devuri/1557f14292832cd84eb9e84fa7c84490 to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| #Header: X-Frame-Options for XSS Protection | |
| add_header X-Frame-Options SAMEORIGIN; | |
| #Header: X-Content-Type Options | |
| add_header X-Content-Type-Options nosniff; | |
| #Header: X-XSS Protection Header | |
| add_header X-XSS-Protection "1; mode=block"; | |
| #Header: Strict-Transport-Security | |
| add_header Strict-Transport-Security "max-age=15768000; includeSubdomains; preload"; | |
| #Header: Content-Security-Policy | |
| add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.api.twitter.com https://gist.github.com https://syndication.twitter.com https://platform.twitter.com https://js-agent.newrelic.com https://*.nr-data.net https://*.wp.com https://*.gravatar.com https://*.wp.com https://pagead2.googlesyndication.com https://ssl.google-analytics.com https://connect.facebook.net https://www.google-analytics.com https://cdnjs.cloudflare.com https://ajax.cloudflare.com; img-src 'self' data: https://pbs.twimg.com https://platform.twitter.com https://syndication.twitter.com https://dashboard.wordpress.com https://s-ssl.wordpress.com https://dashboard.google.com https://wordpress.org https://*.w.org https://*.gravatar.com https://*.wp.com https://ssl.google-analytics.com https://s-static.ak.facebook.com https://www.google-analytics.com; style-src 'self' 'unsafe-inline' https://assets-cdn.github.com https://platform.twitter.com https://*.wp.com https://*.gravatar.com https://fonts.googleapis.com; font-src 'self' data: https://s0.wp.com https://fonts.gstatic.com https://themes.googleusercontent.com; frame-src 'self' https://syndication.twitter.com https://platform.twitter.com https://*.cloudfront.net https://*.wp.com https://*.doubleclick.net https://www.facebook.com https://s-static.ak.facebook.com; object-src 'none'; report-uri https://report-uri.io/report/<ommitted>;"; |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment