File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -61,13 +61,13 @@ http {
6161 #pagespeed off;
6262
6363 # HTTP response headers borrowed from Nextcloud `.htaccess`
64- add_header Referrer-Policy "no-referrer" always;
65- add_header X-Content-Type-Options "nosniff" always;
66- add_header X-Download-Options "noopen" always;
67- add_header X-Frame-Options "SAMEORIGIN" always;
68- add_header X-Permitted-Cross-Domain-Policies "none" always;
69- add_header X-Robots-Tag "none" always;
70- add_header X-XSS-Protection "1; mode=block" always;
64+ add_header Referrer-Policy "no-referrer" always;
65+ add_header X-Content-Type-Options "nosniff" always;
66+ add_header X-Download-Options "noopen" always;
67+ add_header X-Frame-Options "SAMEORIGIN" always;
68+ add_header X-Permitted-Cross-Domain-Policies "none" always;
69+ add_header X-Robots-Tag "noindex, nofollow" always;
70+ add_header X-XSS-Protection "1; mode=block" always;
7171
7272 # Remove X-Powered-By, which is an information leak
7373 fastcgi_hide_header X-Powered-By;
Original file line number Diff line number Diff line change @@ -61,13 +61,13 @@ http {
6161 #pagespeed off;
6262
6363 # HTTP response headers borrowed from Nextcloud `.htaccess`
64- add_header Referrer-Policy "no-referrer" always;
65- add_header X-Content-Type-Options "nosniff" always;
66- add_header X-Download-Options "noopen" always;
67- add_header X-Frame-Options "SAMEORIGIN" always;
68- add_header X-Permitted-Cross-Domain-Policies "none" always;
69- add_header X-Robots-Tag "none" always;
70- add_header X-XSS-Protection "1; mode=block" always;
64+ add_header Referrer-Policy "no-referrer" always;
65+ add_header X-Content-Type-Options "nosniff" always;
66+ add_header X-Download-Options "noopen" always;
67+ add_header X-Frame-Options "SAMEORIGIN" always;
68+ add_header X-Permitted-Cross-Domain-Policies "none" always;
69+ add_header X-Robots-Tag "noindex, nofollow" always;
70+ add_header X-XSS-Protection "1; mode=block" always;
7171
7272 # Remove X-Powered-By, which is an information leak
7373 fastcgi_hide_header X-Powered-By;
Original file line number Diff line number Diff line change @@ -61,13 +61,13 @@ http {
6161 #pagespeed off;
6262
6363 # HTTP response headers borrowed from Nextcloud `.htaccess`
64- add_header Referrer-Policy "no-referrer" always;
65- add_header X-Content-Type-Options "nosniff" always;
66- add_header X-Download-Options "noopen" always;
67- add_header X-Frame-Options "SAMEORIGIN" always;
68- add_header X-Permitted-Cross-Domain-Policies "none" always;
69- add_header X-Robots-Tag "none" always;
70- add_header X-XSS-Protection "1; mode=block" always;
64+ add_header Referrer-Policy "no-referrer" always;
65+ add_header X-Content-Type-Options "nosniff" always;
66+ add_header X-Download-Options "noopen" always;
67+ add_header X-Frame-Options "SAMEORIGIN" always;
68+ add_header X-Permitted-Cross-Domain-Policies "none" always;
69+ add_header X-Robots-Tag "noindex, nofollow" always;
70+ add_header X-XSS-Protection "1; mode=block" always;
7171
7272 # Remove X-Powered-By, which is an information leak
7373 fastcgi_hide_header X-Powered-By;
Original file line number Diff line number Diff line change @@ -61,13 +61,13 @@ http {
6161 #pagespeed off;
6262
6363 # HTTP response headers borrowed from Nextcloud `.htaccess`
64- add_header Referrer-Policy "no-referrer" always;
65- add_header X-Content-Type-Options "nosniff" always;
66- add_header X-Download-Options "noopen" always;
67- add_header X-Frame-Options "SAMEORIGIN" always;
68- add_header X-Permitted-Cross-Domain-Policies "none" always;
69- add_header X-Robots-Tag "none" always;
70- add_header X-XSS-Protection "1; mode=block" always;
64+ add_header Referrer-Policy "no-referrer" always;
65+ add_header X-Content-Type-Options "nosniff" always;
66+ add_header X-Download-Options "noopen" always;
67+ add_header X-Frame-Options "SAMEORIGIN" always;
68+ add_header X-Permitted-Cross-Domain-Policies "none" always;
69+ add_header X-Robots-Tag "noindex, nofollow" always;
70+ add_header X-XSS-Protection "1; mode=block" always;
7171
7272 # Remove X-Powered-By, which is an information leak
7373 fastcgi_hide_header X-Powered-By;
You can’t perform that action at this time.
0 commit comments