Commit e34829c

mo khan <mo@mokhan.ca>
2015-06-28 04:15:19
enable htst and disable loading site in iframe.
1 parent 86041a1
Changed files (1)
templates
templates/default/nginx_unix.erb
@@ -30,6 +30,12 @@ server {
   error_log /var/log/nginx/<%= @domain %>.error.log;
   access_log /var/log/nginx/<%= @domain %>.access.log;
 
+  # enable HTST
+  add_header Strict-Transport-Security "max-age=63072000; includeSubdomains; preload";
+
+  # disable loading in an iframe
+  add_header X-Frame-Options "DENY";
+
   if ($http_user_agent ~* (wget|easouspider|ahrefsbot|httrack|htmlparser|libwww) ) {
     return 403;
   }