diff --git a/build/nginx/configuration/nginx.conf b/build/nginx/configuration/nginx.conf index 4f69430aa2602b7ff5f5fad93ed591739f3d4dd1..4b60457c47e093d4db122f2577e169a039e2d8af 100644 --- a/build/nginx/configuration/nginx.conf +++ b/build/nginx/configuration/nginx.conf @@ -28,6 +28,8 @@ http { '' "default-src 'self'; script-src 'self'; script-src-elem 'self'; script-src-attr 'self'; style-src 'self'; style-src-elem 'self'; style-src-attr 'self'; img-src 'self' data:; font-src 'self'; connect-src 'self'; frame-src 'self'; frame-ancestors 'self' https://scripts.zdv.uni-mainz.de; form-action 'self' metager.org metager.de"; } + underscores_in_headers "on"; + add_header "X-Frame-Options" "sameorigin"; add_header "X-Content-Type-Options" "nosniff"; add_header "ReferrerPolicy" "origin";