diff --git a/config/headersSecurity.conf b/snippets/headersSecurity.conf similarity index 82% rename from config/headersSecurity.conf rename to snippets/headersSecurity.conf index b42e68b..834a875 100644 --- a/config/headersSecurity.conf +++ b/snippets/headersSecurity.conf @@ -1,10 +1,10 @@ add_header Feature-Policy "geolocation 'self'"; -add_header Referrer-Policy "strict-origin" always; +add_header Referrer-Policy "same-origin" always; add_header X-Content-Type-Options "nosniff" always; add_header X-Download-Options noopen; -add_header X-Frame-Options DENY; +add_header X-Frame-Options SAMEORIGIN; add_header X-Permitted-Cross-Domain-Policies none; add_header X-UA-Compatible "IE=edge"; add_header X-XSS-Protection "1; mode=block" always;