How to configure Security Headers in Apache - Quick Sheet
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 |
Enable HSTS Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" Enable X-Frame-Options Header always append X-Frame-Options SAMEORIGIN Enable X-XSS-Protection Header set X-XSS-Protection "1; mode=block" Enable X-Content-Type-Options Header always set X-Content-Type-Options "nosniff" Enable Referrer-Policy Header always set Referrer-Policy "strict-origin" Enable Content Security Policy (CSP) Header always set Content-Security-Policy "default-src 'self'; font-src*;img-src * data:; script-src *; style-src *;" Enable Permissions-Policy Header always set Permissions-Policy "geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()" |
