From e72c482e75c9143644d8f1d9f335cfb84395fb4e Mon Sep 17 00:00:00 2001 From: Fijxu Date: Sun, 4 Dec 2022 17:39:23 -0300 Subject: [PATCH] Fix security headers --- nginx/sites-available/search.zzls.xyz.conf | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/nginx/sites-available/search.zzls.xyz.conf b/nginx/sites-available/search.zzls.xyz.conf index 899df8b..8e114b7 100755 --- a/nginx/sites-available/search.zzls.xyz.conf +++ b/nginx/sites-available/search.zzls.xyz.conf @@ -4,8 +4,6 @@ server { server_name search.zzls.xyz; include configs/general.conf; - include configs/securityheaders.conf; - if ($server_protocol ~* "HTTP/1.0") { return 444; @@ -37,7 +35,10 @@ server { # QUIC add_header Alt-Svc 'h3=":443"; ma=86400'; - # CSP + # CSP + Security Headers + # include configs/securityheaders.conf; + add_header Permissions-Policy "interest-cohort=()" always; + add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always; add_header Content-Security-Policy "default-src 'none'; script-src 'self'; style-src 'self' 'unsafe-inline'; form-action 'self' https://github.com/tiekoetter/searxng/issues/new; font-src 'self'; frame-ancestors 'self'; base-uri 'self'; connect-src 'self' https://overpass-api.de; img-src 'self' data: https://*.tile.openstreetmap.org; frame-src 'self' https://www.youtube-nocookie.com https://invidious.tiekoetter.com https://player.vimeo.com https://www.dailymotion.com https://www.deezer.com https://www.mixcloud.com https://w.soundcloud.com https://embed.spotify.com https://open.spotify.com/" always; quic_retry on;