[Auto-Sync] Atualização das configurações em srvproxy001.itguys.com.br - 2025-09-27 15:42:49
This commit is contained in:
parent
5c2b47d590
commit
44dda8f5fa
|
|
@ -100,13 +100,16 @@ server {
|
|||
resolver_timeout 5s;
|
||||
|
||||
# --- Cabeçalhos de Segurança Otimizados ---
|
||||
add_header Strict-Transport-Security "max-age=15552000; includeSubDomains" always;
|
||||
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;
|
||||
add_header X-Content-Type-Options "nosniff" always;
|
||||
add_header X-Frame-Options "SAMEORIGIN" always;
|
||||
add_header Referrer-Policy "no-referrer" always;
|
||||
add_header Permissions-Policy "geolocation=(), midi=(), sync-xhr=(), microphone=(), camera=(), magnetometer=(), gyroscope=(), fullscreen=(), payment=()" always;
|
||||
add_header Content-Security-Policy "default-src 'none'; base-uri 'none'; manifest-src 'self'; script-src 'nonce-hM7OrLSVwumFk18lv8kzCmeGt8EDVd/0GWKxgzqi5U' 'strict-dynamic'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https://srvoffice001.itguys.com.br; font-src 'self' data:; connect-src 'self'; media-src 'self' data:; frame-src 'self' blob: https://srvoffice001.itguys.com.br; frame-ancestors 'self' https://srvoffice001.itguys.com.br; form-action 'self' https://srvoffice001.itguys.com.br;" always;
|
||||
proxy_hide_header "X-Content-Type-Options";
|
||||
proxy_hide_header "X-Frame-Options"; # Esconde header do backend para não duplicar
|
||||
proxy_hide_header "Feature-Policy";
|
||||
proxy_hide_header "Content-Security-Policy"; # Garante que nosso CSP seja o único aplicado.
|
||||
|
||||
# --- Bloco de Compressão ---
|
||||
brotli on;
|
||||
|
|
|
|||
Loading…
Reference in New Issue