update headers with CSP

This commit is contained in:
Dominic Reich 2019-03-16 20:22:00 +01:00
parent a02cab5236
commit 7c9f99038f
No known key found for this signature in database
GPG key ID: 2664FE98B15DDE4F

View file

@ -8,6 +8,7 @@
Strict-Transport-Security = "max-age=31536000; includeSubDomains; preload"
Cache-Control = "public, max-age=31536000"
Referrer-Policy = "strict-origin-when-cross-origin"
Content-Security-Policy = "default-src https:"
X-Content-Type-Options = "nosniff"
X-Frame-Options = "DENY"
X-XSS-Protection = "1; mode=block"