Skip to content

Instantly share code, notes, and snippets.

@mrkdevelopment
Last active February 16, 2024 05:24
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save mrkdevelopment/e5e7c274c11cb9ecd4274229df60f14e to your computer and use it in GitHub Desktop.
Save mrkdevelopment/e5e7c274c11cb9ecd4274229df60f14e to your computer and use it in GitHub Desktop.
Security headers for cloudways
# Security Headers
<IfModule mod_headers.c>
Header set X-XSS-Protection "1; mode=block"
Header set X-Frame-Options "SAMEORIGIN"
Header set X-Content-Type-Options "nosniff"
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
Header set Content-Security-Policy "default-src 'self'"
Header set Referrer-Policy "same-origin"
Header set Feature-Policy "geolocation 'self'; vibrate 'none'"
</IfModule>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment