mirror of
https://github.com/d0zingcat/ghost-docker.git
synced 2026-06-02 23:16:49 +00:00
Caddy: Add option to have a separate Admin domain
- Our setup docs recommend having Ghost Admin on a separate domain from the content domain - This lets users optionally set this up if they want whilst continuing to align Admin <-> content domain through templates
This commit is contained in:
12
caddy/snippets/SecurityHeaders
Normal file
12
caddy/snippets/SecurityHeaders
Normal file
@@ -0,0 +1,12 @@
|
||||
header {
|
||||
# Enable HSTS
|
||||
Strict-Transport-Security max-age=31536000;
|
||||
# Prevent embedding in frames
|
||||
X-Frame-Options DENY
|
||||
# Enable XSS protection
|
||||
X-XSS-Protection "1; mode=block"
|
||||
# Prevent MIME sniffing
|
||||
X-Content-Type-Options nosniff
|
||||
# Referrer policy
|
||||
Referrer-Policy strict-origin-when-cross-origin
|
||||
}
|
||||
Reference in New Issue
Block a user