Jump to content

Nginx:Security Header: Difference between revisions

From Wiki
Created page with "Tambahkan berikut ini di file nginx.conf di bawah blok server. ===Content Security Policy=== add_header Content-Security-Policy "default-src 'self';"; ===X-Frame-Options=== add_header X-Frame-Options "DENY"; ===X-XSS-Protection=== add_header X-XSS-Protection "1; mode=block"; ===X-Content-Type-Options=== add_header X-Content-Type-Options nosniff; ===HTTP Strict Transport Security=== add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; prelo..."
 
No edit summary
 
(One intermediate revision by the same user not shown)
Line 2: Line 2:


===Content Security Policy===
===Content Security Policy===
add_header Content-Security-Policy "default-src 'self';";
<syntaxhighlight lang="apache">add_header Content-Security-Policy "default-src 'self';";</syntaxhighlight>


===X-Frame-Options===
===X-Frame-Options===
add_header X-Frame-Options "DENY";
<syntaxhighlight lang="apache">add_header X-Frame-Options "DENY";</syntaxhighlight>


===X-XSS-Protection===
===X-XSS-Protection===
add_header X-XSS-Protection "1; mode=block";
<syntaxhighlight lang="apache">add_header X-XSS-Protection "1; mode=block";</syntaxhighlight>


===X-Content-Type-Options===
===X-Content-Type-Options===
add_header X-Content-Type-Options nosniff;
<syntaxhighlight lang="apache">add_header X-Content-Type-Options nosniff;</syntaxhighlight>


===HTTP Strict Transport Security===
===HTTP Strict Transport Security===
add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload';
<syntaxhighlight lang="apache">add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload';</syntaxhighlight>


==Source==
==Source==
*[https://beaglesecurity.com/blog/article/hardening-server-security-by-implementing-security-headers.html beaglesecurity.com]
*[https://beaglesecurity.com/blog/article/hardening-server-security-by-implementing-security-headers.html beaglesecurity.com]
[[Category:Server]]
[[Category:Web Server]]
[[Category:Nginx]]
[[Category:Security]]

Latest revision as of 17:19, 30 August 2022

Tambahkan berikut ini di file nginx.conf di bawah blok server.

Content Security Policy

add_header Content-Security-Policy "default-src 'self';";

X-Frame-Options

add_header X-Frame-Options "DENY";

X-XSS-Protection

add_header X-XSS-Protection "1; mode=block";

X-Content-Type-Options

add_header X-Content-Type-Options nosniff;

HTTP Strict Transport Security

add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload';

Source