Split out cross origin security headers
This commit is contained in:
parent
e64e242e42
commit
03149c183c
@ -16,6 +16,7 @@ server {
|
|||||||
include snippets/universal_paths.conf;
|
include snippets/universal_paths.conf;
|
||||||
include snippets/hsts.conf;
|
include snippets/hsts.conf;
|
||||||
include snippets/security.conf;
|
include snippets/security.conf;
|
||||||
|
include snippets/cross-origin-security.conf;
|
||||||
include snippets/quic.conf;
|
include snippets/quic.conf;
|
||||||
include snippets/proxy.conf;
|
include snippets/proxy.conf;
|
||||||
proxy_hide_header Content-Security-Policy;
|
proxy_hide_header Content-Security-Policy;
|
||||||
|
11
etc/nginx/snippets/cross-origin-security.conf
Normal file
11
etc/nginx/snippets/cross-origin-security.conf
Normal file
@ -0,0 +1,11 @@
|
|||||||
|
# CORP, COOP, and COEP headers
|
||||||
|
# Meant to be used globally, but some apps may need a manual overwrite, so this is split out from security.conf
|
||||||
|
|
||||||
|
proxy_hide_header Cross-Origin-Resource-Policy;
|
||||||
|
add_header Cross-Origin-Resource-Policy cross-origin always;
|
||||||
|
|
||||||
|
proxy_hide_header Cross-Origin-Opener-Policy;
|
||||||
|
add_header Cross-Origin-Opener-Policy same-origin always;
|
||||||
|
|
||||||
|
proxy_hide_header Cross-Origin-Opener-Policy;
|
||||||
|
Cross-Origin-Embedder-Policy require-corp always;
|
@ -13,12 +13,6 @@ add_header X-Content-Type-Options "nosniff" always;
|
|||||||
proxy_hide_header X-Frame-Options;
|
proxy_hide_header X-Frame-Options;
|
||||||
add_header X-Frame-Options "SAMEORIGIN" always;
|
add_header X-Frame-Options "SAMEORIGIN" always;
|
||||||
|
|
||||||
proxy_hide_header Cross-Origin-Resource-Policy;
|
|
||||||
add_header Cross-Origin-Resource-Policy cross-origin always;
|
|
||||||
|
|
||||||
proxy_hide_header Cross-Origin-Opener-Policy;
|
|
||||||
add_header Cross-Origin-Opener-Policy same-origin always;
|
|
||||||
|
|
||||||
# Obsolete and replaced by Content-Security-Policy
|
# Obsolete and replaced by Content-Security-Policy
|
||||||
# Only here to pass Hardenize checks
|
# Only here to pass Hardenize checks
|
||||||
proxy_hide_header X-XSS-Protection;
|
proxy_hide_header X-XSS-Protection;
|
||||||
|
Loading…
x
Reference in New Issue
Block a user