From 2d8917470ae6ba81f820767c90424c8b1aadd856 Mon Sep 17 00:00:00 2001 From: Patrick Uiterwijk Date: Fri, 4 May 2018 02:42:36 +0200 Subject: [PATCH] Set security headers for dl.fp.o Signed-off-by: Patrick Uiterwijk --- .../files/httpd/dl.fedoraproject.org/securityheaders.conf | 5 +++++ 1 file changed, 5 insertions(+) create mode 100644 roles/download/files/httpd/dl.fedoraproject.org/securityheaders.conf diff --git a/roles/download/files/httpd/dl.fedoraproject.org/securityheaders.conf b/roles/download/files/httpd/dl.fedoraproject.org/securityheaders.conf new file mode 100644 index 0000000000..c7109a16a6 --- /dev/null +++ b/roles/download/files/httpd/dl.fedoraproject.org/securityheaders.conf @@ -0,0 +1,5 @@ +Header always set X-Frame-Options "DENY" +Header always set X-Xss-Protection "1; mode=block" +Header always set X-Content-Type-Options "nosniff" +Header always set Referrer-Policy "same-origin" +Header always set Content-Security-Policy "default-src 'none'"