Skip to content

Instantly share code, notes, and snippets.

@KryptikOne
Last active May 30, 2019 14:54
Show Gist options
  • Select an option

  • Save KryptikOne/9e26a3c683d63f3e06e49f04141b4ad2 to your computer and use it in GitHub Desktop.

Select an option

Save KryptikOne/9e26a3c683d63f3e06e49f04141b4ad2 to your computer and use it in GitHub Desktop.

Revisions

  1. KryptikOne revised this gist May 30, 2019. 1 changed file with 1 addition and 1 deletion.
    2 changes: 1 addition & 1 deletion security-headers.txt
    Original file line number Diff line number Diff line change
    @@ -1,7 +1,7 @@
    Header set Cache-Control "max-age=604800, public"
    Header set X-Content-Type-Options nosniff
    Header set X-XSS-Protection "1; mode=block"
    Header set Strict-Transport-Security "max-age=31536000" env=HTTPS
    Header set Strict-Transport-Security "max-age=31536000; includeSubDomains;" env=HTTPS
    Header always append X-Frame-Options SAMEORIGIN
    Header set Referrer-Policy: no-referrer-when-downgrade
    Header always edit Set-Cookie (.*) "$1; HTTPOnly; Secure; SameSite=strict;"
  2. KryptikOne renamed this gist May 30, 2019. 1 changed file with 0 additions and 0 deletions.
    File renamed without changes.
  3. KryptikOne revised this gist May 30, 2019. No changes.
  4. KryptikOne created this gist May 10, 2019.
    8 changes: 8 additions & 0 deletions wp-security-headers.txt
    Original file line number Diff line number Diff line change
    @@ -0,0 +1,8 @@
    Header set Cache-Control "max-age=604800, public"
    Header set X-Content-Type-Options nosniff
    Header set X-XSS-Protection "1; mode=block"
    Header set Strict-Transport-Security "max-age=31536000" env=HTTPS
    Header always append X-Frame-Options SAMEORIGIN
    Header set Referrer-Policy: no-referrer-when-downgrade
    Header always edit Set-Cookie (.*) "$1; HTTPOnly; Secure; SameSite=strict;"
    Header set Content-Security-Policy "default-src 'self' ADD_ADDITIONAL_SOURCES_HERE; script-src 'self' ADD_ADDITIONAL_SOURCES_HERE; style-src 'self' ADD_ADDITIONAL_SOURCES_HERE; font-src 'self' ADD_ADDITIONAL_SOURCES_HERE; img-src 'self' ADD_ADDITIONAL_SOURCES_HERE;"