From 6227097204ba08139345534dd85b758e05f6c1fa Mon Sep 17 00:00:00 2001 From: Edwin Lyon <53972157+practical-engelbart@users.noreply.github.com> Date: Tue, 15 Sep 2020 01:56:50 -0700 Subject: [PATCH] Update mailcow.conf --- nginx/mailcow.conf | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/nginx/mailcow.conf b/nginx/mailcow.conf index 2854710..604a277 100644 --- a/nginx/mailcow.conf +++ b/nginx/mailcow.conf @@ -37,11 +37,12 @@ server { resolver 1.1.1.1:53 1.0.0.1:53 '[2606:4700:4700::1111]:53' '[2606:4700:4700::1001]:53' valid=300s; resolver_timeout 30s; + add_header Strict-Transport-Security "max-age=63072000"; add_header X-Frame-Options "SAMEORIGIN" always; add_header X-XSS-Protection "1; mode=block" always; add_header X-Content-Type-Options "nosniff" always; - add_header Referrer-Policy "strict-origin-when-cross-origin"; - add_header Content-Security-Policy "upgrade-insecure-requests; default-src https:" always; + add_header Referrer-Policy "strict-origin-when-cross-origin" always; + add_header Content-Security-Policy "upgrade-insecure-requests" always; add_header Feature-policy "accelerometer 'none'; camera 'none'; geolocation 'none'; gyroscope 'none'; magnetometer 'none'; microphone 'none'; payment 'none'" always; location ^~ /.well-known/acme-challenge/ {