فهرست منبع

web: set security headers also for non HTTPS

Fixes: #493
Jakub Onderka 4 سال پیش
والد
کامیت
2a0120d
2فایلهای تغییر یافته به همراه4 افزوده شده و 2 حذف شده
  1. 4 0
      web/rootfs/defaults/meet.conf
  2. 0 2
      web/rootfs/defaults/ssl.conf

+ 4 - 0
web/rootfs/defaults/meet.conf

@@ -11,6 +11,10 @@ ssi_types application/x-javascript application/javascript;
 index index.html index.htm;
 error_page 404 /static/404.html;
 
+# Security headers
+add_header X-Content-Type-Options nosniff;
+add_header X-XSS-Protection "1; mode=block";
+
 location = /config.js {
     alias /config/config.js;
 }

+ 0 - 2
web/rootfs/defaults/ssl.conf

@@ -20,5 +20,3 @@ ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-
 
 # headers
 add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload";
-add_header X-Content-Type-Options nosniff;
-add_header X-XSS-Protection "1; mode=block";