diff options
| author | schererleander <leander@schererleander.de> | 2025-05-30 06:23:34 +0200 |
|---|---|---|
| committer | schererleander <leander@schererleander.de> | 2025-05-30 06:23:34 +0200 |
| commit | 27fb01cc1a58e245793b10d78a0c114781d4ba16 (patch) | |
| tree | c3f3c831daa1105fcc73256995266f96d0f8e14b /hosts/vps/configuration.nix | |
| parent | c8672e718fcb73d07ddab00b95eb45b53f1ffe0f (diff) | |
hardened nginx
Diffstat (limited to 'hosts/vps/configuration.nix')
| -rw-r--r-- | hosts/vps/configuration.nix | 19 |
1 files changed, 3 insertions, 16 deletions
diff --git a/hosts/vps/configuration.nix b/hosts/vps/configuration.nix index b309502..d688cf9 100644 --- a/hosts/vps/configuration.nix +++ b/hosts/vps/configuration.nix @@ -52,27 +52,14 @@ sslCiphers = "AES256+EECDH:AES256+EDH:!aNULL"; appendHttpConfig = '' - # Add HSTS header with preloading to HTTPS requests. - # Adding this header to HTTP requests is discouraged map $scheme $hsts_header { https "max-age=31536000; includeSubdomains; preload"; } add_header Strict-Transport-Security $hsts_header; - - # Enable CSP for your services. - #add_header Content-Security-Policy "script-src 'self'; object-src 'none'; base-uri 'none';" always; - - # Minimize information leaked to other domains - add_header 'Referrer-Policy' 'origin-when-cross-origin'; - - # Disable embedding as a frame + add_header Content-Security-Policy "script-src 'self'; object-src 'none'; base-uri 'none';" always; + add_header 'Referrer-Policy' same-origin always; add_header X-Frame-Options DENY; - - # Prevent injection of code in other mime types (XSS Attacks) - add_header X-Content-Type-Options nosniff; - - # This might create errors - proxy_cookie_path / "/; secure; HttpOnly; SameSite=strict"; + add_header X-Content-Type-Options nosniff always; ''; virtualHosts."schererleander.de" = { |
