Complete 'HTTP Security Header' documentation.
This commit is contained in:
@ -41,7 +41,7 @@ Header always set X-Frame-Options "SAMEORIGIN"
|
||||
# - if it detects an attack rather than sanitising
|
||||
# - the script.
|
||||
# -
|
||||
Header always set X-Content-Type-Options "nosniff"
|
||||
Header always set X-XSS-Protection "1; mode=block"
|
||||
|
||||
|
||||
# - X-Content-Type-Options
|
||||
|
Reference in New Issue
Block a user