Add more security headers

... and deprecate "X-Content-Security-Policy" and "X-WebKit-CSP"
This commit is contained in:
Dirk Wetter 2025-01-16 21:18:47 +01:00
parent 701c606eac
commit 8000885371

View File

@ -3438,13 +3438,17 @@ run_security_headers() {
for header_and_svrty in "X-Frame-Options OK" \ for header_and_svrty in "X-Frame-Options OK" \
"X-Content-Type-Options OK" \ "X-Content-Type-Options OK" \
"Content-Security-Policy OK" \ "Content-Security-Policy OK" \
"X-Content-Security-Policy OK" \ "X-Content-Security-Policy INFO" \
"X-WebKit-CSP OK" \ "X-WebKit-CSP INFO" \
"Content-Security-Policy-Report-Only OK" \ "Content-Security-Policy-Report-Only OK" \
"Expect-CT OK" \ "Expect-CT OK" \
"Permissions-Policy OK" \ "Permissions-Policy OK" \
"Cross-Origin-Opener-Policy INFO" \
"Cross-Origin-Resource-Policy INFO" \
"Cross-Origin-Embedder-Policy INFO" \
"X-XSS-Protection INFO" \ "X-XSS-Protection INFO" \
"Access-Control-Allow-Origin INFO" \ "Access-Control-Allow-Origin INFO" \
"Access-Control-Allow-Credentials INFO" \
"Upgrade INFO" \ "Upgrade INFO" \
"X-Served-By INFO" \ "X-Served-By INFO" \
"Referrer-Policy INFO" \ "Referrer-Policy INFO" \