
17 Mar
2015
17 Mar
'15
5:30 a.m.
Signed-off-by: Julien Goodwin <jgoodwin@studio442.com.au> --- docs/apache.conf.ex | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/docs/apache.conf.ex b/docs/apache.conf.ex index cd26907..32a1114 100644 --- a/docs/apache.conf.ex +++ b/docs/apache.conf.ex @@ -23,6 +23,10 @@ # HTTP STS Header always set Strict-Transport-Security "max-age=31536000; includeSubdomains;" + + Header always set X-Frame-Options "DENY" + Header always set X-Content-Type-Options "nosniff" + Header always set X-XSS-Protection "1; mode=block" </VirtualHost> <VirtualHost *:80> -- 2.1.4