diff --git a/roles/download/files/httpd/dl.fedoraproject.org/securityheaders.conf b/roles/download/files/httpd/dl.fedoraproject.org/securityheaders.conf new file mode 100644 index 0000000000..c7109a16a6 --- /dev/null +++ b/roles/download/files/httpd/dl.fedoraproject.org/securityheaders.conf @@ -0,0 +1,5 @@ +Header always set X-Frame-Options "DENY" +Header always set X-Xss-Protection "1; mode=block" +Header always set X-Content-Type-Options "nosniff" +Header always set Referrer-Policy "same-origin" +Header always set Content-Security-Policy "default-src 'none'"