40 lines
1.1 KiB
YAML
40 lines
1.1 KiB
YAML
nelmio_security:
|
|
# prevents framing of the entire site
|
|
clickjacking:
|
|
paths:
|
|
'^/.*': DENY
|
|
|
|
# disables content type sniffing for script resources
|
|
content_type:
|
|
nosniff: true
|
|
|
|
# Send a full URL in the `Referer` header when performing a same-origin request,
|
|
# only send the origin of the document to secure destination (HTTPS->HTTPS),
|
|
# and send no header to a less secure destination (HTTPS->HTTP).
|
|
# If `strict-origin-when-cross-origin` is not supported, use `no-referrer` policy,
|
|
# no referrer information is sent along with requests.
|
|
referrer_policy:
|
|
enabled: true
|
|
policies:
|
|
- 'no-referrer'
|
|
- 'strict-origin-when-cross-origin'
|
|
|
|
forced_ssl:
|
|
hsts_max_age: 31536000
|
|
hsts_preload: true
|
|
csp:
|
|
enabled: true
|
|
enforce:
|
|
default-src:
|
|
- 'self'
|
|
img-src:
|
|
- 'self'
|
|
- 'data:'
|
|
style-src:
|
|
- 'self'
|
|
- 'unsafe-inline'
|
|
form-action:
|
|
- 'self'
|
|
object-src:
|
|
- 'none'
|