9f495aa2 by Jeff Balicki

ss

Signed-off-by: Jeff <jeff@gotenzing.com>
1 parent 51165aea
......@@ -153,9 +153,11 @@ ModPagespeed off
Header set X-Content-Type-Options "nosniff"
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
# Header set Content-Security-Policy ...
Header add Content-Security-Policy "default-src 'self';"
Header set Referrer-Policy "same-origin"
Header set Feature-Policy "geolocation 'self'; vibrate 'none'"
#Header always edit Set-Cookie (.*) "$1; HttpOnly"
#Header always edit Set-Cookie (.*) "$1; Secure"
</IfModule>
<IfModule mod_rewrite.c>
......