Skip to content

Instantly share code, notes, and snippets.

@praveencs87
Created November 3, 2020 11:59
Show Gist options
  • Save praveencs87/6640a4bf743744e35a2d160c4298be33 to your computer and use it in GitHub Desktop.
Save praveencs87/6640a4bf743744e35a2d160c4298be33 to your computer and use it in GitHub Desktop.
Security Headers
<IfModule mod_headers.c>
Header always append X-Frame-Options SAMEORIGIN
Header always set Strict-Transport-Security "max-age=10886400; includeSubDomains"
Header set X-XSS-Protection "1; mode=block"
Header set Content-Security-Policy default-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self';
Header set X-Content-Type-Options nosniff
Header set X-Permitted-Cross-Domain-Policies "none"
Header set Referrer-Policy "no-referrer"
Header set Feature-Policy "geolocation 'self'; vibrate 'none'"
</IfModule>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment