Signed-off-by: Julien Goodwin <jgoodwin(a)studio442.com.au>
---
docs/apache.conf.ex | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/docs/apache.conf.ex b/docs/apache.conf.ex
index cd26907..32a1114 100644
--- a/docs/apache.conf.ex
+++ b/docs/apache.conf.ex
@@ -23,6 +23,10 @@
# HTTP STS
Header always set Strict-Transport-Security "max-age=31536000;
includeSubdomains;"
+
+ Header always set X-Frame-Options "DENY"
+ Header always set X-Content-Type-Options "nosniff"
+ Header always set X-XSS-Protection "1; mode=block"
</VirtualHost>
<VirtualHost *:80>
--
2.1.4