File tree 3 files changed +4
-10
lines changed
rootfs/usr/local/nginx/conf/conf.d/include
3 files changed +4
-10
lines changed Original file line number Diff line number Diff line change @@ -2,6 +2,6 @@ more_set_headers "X-XSS-Protection: 0";
2
2
more_set_headers "X-Frame-Options: SAMEORIGIN";
3
3
more_set_headers "X-Content-Type-Options: nosniff";
4
4
more_set_headers "Referrer-Policy: strict-origin-when-cross-origin";
5
- more_set_headers "Content-Security-Policy: $content_security_policy";
5
+ more_set_headers "Content-Security-Policy: $content_security_policy"; # if not set by upstream: upgrade-insecure-requests, else upstreams value is used
6
6
7
- more_set_headers "Strict-Transport-Security: $hsts_header";
7
+ more_set_headers "Strict-Transport-Security: $hsts_header"; # means: max-age=63072000; includeSubDomains; preload
Original file line number Diff line number Diff line change @@ -6,8 +6,5 @@ proxy_set_header X-Real-IP $remote_addr;
6
6
#proxy_set_header Accept-Encoding "";
7
7
proxy_set_header Host $host;
8
8
9
- proxy_set_header Early-Data $ssl_early_data;
10
- proxy_ssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3;
11
- proxy_ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA256:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA;
12
-
13
9
proxy_http_version 1.1;
10
+ proxy_set_header Early-Data $ssl_early_data;
Original file line number Diff line number Diff line change @@ -6,9 +6,6 @@ proxy_set_header X-Real-IP $remote_addr;
6
6
#proxy_set_header Accept-Encoding "";
7
7
proxy_set_header Host $host;
8
8
9
- proxy_set_header Early-Data $ssl_early_data;
10
- proxy_ssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3;
11
- proxy_ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA256:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA;
12
-
13
9
proxy_http_version 1.1;
10
+ proxy_set_header Early-Data $ssl_early_data;
14
11
proxy_pass $forward_scheme://$server:$port$request_uri;
You can’t perform that action at this time.
0 commit comments