Advertisement
arabtion

Untitled

Feb 18th, 2020
136
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.77 KB | None | 0 0
  1.  
  2. # security headers
  3. add_header X-Frame-Options "SAMEORIGIN" always;
  4. add_header X-XSS-Protection "1; mode=block" always;
  5. add_header X-Content-Type-Options "nosniff" always;
  6. add_header Referrer-Policy "no-referrer-when-downgrade" always;
  7. add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
  8. add_header X-Frame-Options DENY;
  9. add_header X-Content-Type-Options nosniff;
  10. add_header 'Access-Control-Allow-Origin' '*';
  11. add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS';
  12. add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range';
  13. add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range';
  14. # . files
  15. location ~ /\.(?!well-known) {
  16. deny all;
  17. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement