51165aea by Jeff Balicki

htaccess

Signed-off-by: Jeff <jeff@gotenzing.com>
1 parent 97833bf7
......@@ -153,6 +153,7 @@ ModPagespeed off
Header set X-Content-Type-Options "nosniff"
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
# Header set Content-Security-Policy ...
Header add Content-Security-Policy "default-src 'self';"
Header set Referrer-Policy "same-origin"
Header set Feature-Policy "geolocation 'self'; vibrate 'none'"
</IfModule>
......