]> git.ipfire.org Git - ipfire-2.x.git/blobdiff - config/httpd/vhosts.d/ipfire-interface.conf
prevent loading resources from external sites
[ipfire-2.x.git] / config / httpd / vhosts.d / ipfire-interface.conf
index 5c7ddc7197cbb1a0dcb9cf513d86a9510ef36cfa..b709944047b3c74a56c33d4646a3816bea4f1f3e 100644 (file)
@@ -7,6 +7,7 @@
     RewriteRule .* - [F]
 
     Header always set X-Content-Type-Options nosniff
+    Header always set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'"
 
     <Directory /srv/web/ipfire/html>
         Options ExecCGI