Nginx:Security Header: Difference between revisions
Appearance
Created page with "Tambahkan berikut ini di file nginx.conf di bawah blok server. ===Content Security Policy=== add_header Content-Security-Policy "default-src 'self';"; ===X-Frame-Options=== add_header X-Frame-Options "DENY"; ===X-XSS-Protection=== add_header X-XSS-Protection "1; mode=block"; ===X-Content-Type-Options=== add_header X-Content-Type-Options nosniff; ===HTTP Strict Transport Security=== add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; prelo..." |
No edit summary |
||
| (One intermediate revision by the same user not shown) | |||
| Line 2: | Line 2: | ||
===Content Security Policy=== | ===Content Security Policy=== | ||
<syntaxhighlight lang="apache">add_header Content-Security-Policy "default-src 'self';";</syntaxhighlight> | |||
===X-Frame-Options=== | ===X-Frame-Options=== | ||
<syntaxhighlight lang="apache">add_header X-Frame-Options "DENY";</syntaxhighlight> | |||
===X-XSS-Protection=== | ===X-XSS-Protection=== | ||
<syntaxhighlight lang="apache">add_header X-XSS-Protection "1; mode=block";</syntaxhighlight> | |||
===X-Content-Type-Options=== | ===X-Content-Type-Options=== | ||
<syntaxhighlight lang="apache">add_header X-Content-Type-Options nosniff;</syntaxhighlight> | |||
===HTTP Strict Transport Security=== | ===HTTP Strict Transport Security=== | ||
<syntaxhighlight lang="apache">add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload';</syntaxhighlight> | |||
==Source== | ==Source== | ||
*[https://beaglesecurity.com/blog/article/hardening-server-security-by-implementing-security-headers.html beaglesecurity.com] | *[https://beaglesecurity.com/blog/article/hardening-server-security-by-implementing-security-headers.html beaglesecurity.com] | ||
[[Category:Server]] | |||
[[Category:Web Server]] | |||
[[Category:Nginx]] | |||
[[Category:Security]] | |||
Latest revision as of 17:19, 30 August 2022
Tambahkan berikut ini di file nginx.conf di bawah blok server.
Content Security Policy
add_header Content-Security-Policy "default-src 'self';";
X-Frame-Options
add_header X-Frame-Options "DENY";
X-XSS-Protection
add_header X-XSS-Protection "1; mode=block";
X-Content-Type-Options
add_header X-Content-Type-Options nosniff;
HTTP Strict Transport Security
add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload';