Skip to content

Add Content Security Policy to webserver configuration#55

Open
pablo-knight wants to merge 2 commits intomasterfrom
csp
Open

Add Content Security Policy to webserver configuration#55
pablo-knight wants to merge 2 commits intomasterfrom
csp

Conversation

@pablo-knight
Copy link
Contributor

No description provided.

@pablo-knight pablo-knight requested a review from plettich August 25, 2022 13:23
@pablo-knight
Copy link
Contributor Author

working on #41


# CSP Content-Security-Policy, protect website from click-jacking attacks.
# Allow from self but DENY others
Header set Content-Security-Policy "frame-ancestors 'self';"
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do You use frame-ancestors here but default-src in the nginx config?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you're right, should be like the apache config "frame-ancestors"

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

more info:
https://docs.w3cub.com/http/headers/content-security-policy/frame-ancestors
We should additional prevent: 'unsafe-eval' or 'unsafe-inline', frame-ancestors did this as default.

todo:
[ ] test this on a loadbalancer / haproxy

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants