From 14bd7fdd7ae4ba229e1e8fb61f079659d15f642f Mon Sep 17 00:00:00 2001 From: Patrick Uiterwijk Date: Fri, 4 May 2018 12:12:17 +0200 Subject: [PATCH] dl.fp.o has images Signed-off-by: Patrick Uiterwijk --- .../files/httpd/dl.fedoraproject.org/securityheaders.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/roles/download/files/httpd/dl.fedoraproject.org/securityheaders.conf b/roles/download/files/httpd/dl.fedoraproject.org/securityheaders.conf index cb7969e2a7..2494206e0c 100644 --- a/roles/download/files/httpd/dl.fedoraproject.org/securityheaders.conf +++ b/roles/download/files/httpd/dl.fedoraproject.org/securityheaders.conf @@ -2,5 +2,5 @@ Header always set X-Frame-Options "DENY" Header always set X-Xss-Protection "1; mode=block" Header always set X-Content-Type-Options "nosniff" Header always set Referrer-Policy "same-origin" -Header always set Content-Security-Policy "default-src 'none'" +Header always set Content-Security-Policy "default-src 'none'; img-src 'self'" Header always add Strict-Transport-Security "max-age=31536000; preload"