Skip to content

Commit 74a297a

Browse files
author
Till Brehm
committed
Merge branch 'patch-3' into 'stable-3.1'
Add Content-Security-Policy header and friends. See merge request ispconfig/ispconfig3!824
2 parents 06cf8f6 + b5dd05a commit 74a297a

File tree

1 file changed

+8
-2
lines changed

1 file changed

+8
-2
lines changed

install/tpl/apache_ispconfig.vhost.master

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -88,8 +88,14 @@ NameVirtualHost *:<tmpl_var name="vhost_port">
8888
</tmpl_if>
8989

9090
<IfModule mod_headers.c>
91-
Header setifempty add Strict-Transport-Security "max-age=15768000"
92-
RequestHeader unset Proxy early
91+
# ISPConfig 3.1 currently requires unsafe-line for both scripts and styles, as well as unsafe-eval
92+
Header set Content-Security-Policy "default-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src 'self' data:; object-src 'none'; upgrade-insecure-requests"
93+
Header set X-Content-Type-Options: nosniff
94+
Header set X-Frame-Options: SAMEORIGIN
95+
Header set X-XSS-Protection: "1; mode=block"
96+
Header always edit Set-Cookie (.*) "$1; HTTPOnly; Secure"
97+
Header setifempty Strict-Transport-Security "max-age=15768000"
98+
RequestHeader unset Proxy early
9399
</IfModule>
94100

95101
<tmpl_if name='apache_version' op='>=' value='2.3.3' format='version'>

0 commit comments

Comments
 (0)