Skip to content
Snippets Groups Projects

Add security HTTP headers to nginx config

Merged Axel Bocciarelli requested to merge security-headers into main

Following the cybersecurity training.

You should also consider adding an immutable 1-year cache to CSS and JS assets for performance reasons (as long as they have hashes in their filenames for cache busting, which they should already; so just need to check if there are any JS/CSS file without hashes in their file names).

Adding the CSP header is a lot more complicated, so I didn't do it. You could try adding one in report mode to see.

Edited by Axel Bocciarelli

Merge request reports

Loading
Loading

Activity

Filter activity
  • Approvals
  • Assignees & reviewers
  • Comments (from bots)
  • Comments (from users)
  • Commits & branches
  • Edits
  • Labels
  • Lock status
  • Mentions
  • Merge request status
  • Tracking
Please register or sign in to reply
Loading