Skip to content

Commit f23e656

Browse files
authored
fix: fix for clickjacking that mirrors namada.net (#2297)
1 parent d47df96 commit f23e656

File tree

1 file changed

+21
-10
lines changed

1 file changed

+21
-10
lines changed

docker/namadillo/nginx.conf

Lines changed: 21 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,23 @@
11
server {
2-
listen 80;
3-
server_name localhost;
4-
location / {
5-
root /usr/share/nginx/html;
6-
index index.html index.htm;
7-
try_files $uri $uri/ $uri.html /index.html;
8-
add_header Cross-Origin-Embedder-Policy "credentialless";
9-
add_header Cross-Origin-Opener-Policy "same-origin";
10-
}
11-
gzip off;
2+
listen 80;
3+
server_name localhost;
4+
5+
location / {
6+
root /usr/share/nginx/html;
7+
index index.html index.htm;
8+
try_files $uri $uri/ $uri.html /index.html;
9+
add_header Cross-Origin-Embedder-Policy "credentialless" always;
10+
add_header Cross-Origin-Opener-Policy "same-origin" always;
11+
add_header Cross-Origin-Resource-Policy "same-origin" always;
12+
add_header Expect-CT "max-age=0" always;
13+
add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), usb=(), payment=()" always;
14+
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always; # only effective over HTTPS
15+
add_header X-Frame-Options "DENY" always;
16+
add_header X-Content-Type-Options "nosniff" always;
17+
add_header X-XSS-Protection "0" always;
18+
}
19+
20+
21+
22+
gzip off;
1223
}

0 commit comments

Comments
 (0)