From 0b2461a655684c6d706d30a081350e59601eab33 Mon Sep 17 00:00:00 2001 From: Paulo Schneider Date: Fri, 19 Feb 2016 21:13:47 +0000 Subject: Add recommended security headers from #618 --- service/pixelated/config/site.py | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) (limited to 'service/pixelated/config/site.py') diff --git a/service/pixelated/config/site.py b/service/pixelated/config/site.py index 8806366a..6a29c478 100644 --- a/service/pixelated/config/site.py +++ b/service/pixelated/config/site.py @@ -2,12 +2,15 @@ from twisted.web.server import Site, Request class AddCSPHeaderRequest(Request): - HEADER_VALUES = "default-src 'self'; style-src 'self' 'unsafe-inline'" + CSP_HEADER_VALUES = "default-src 'self'; style-src 'self' 'unsafe-inline'" def process(self): - self.setHeader("Content-Security-Policy", self.HEADER_VALUES) - self.setHeader("X-Content-Security-Policy", self.HEADER_VALUES) - self.setHeader("X-Webkit-CSP", self.HEADER_VALUES) + self.setHeader('Content-Security-Policy', self.CSP_HEADER_VALUES) + self.setHeader('X-Content-Security-Policy', self.CSP_HEADER_VALUES) + self.setHeader('X-Webkit-CSP', self.CSP_HEADER_VALUES) + self.setHeader('X-Frame-Options', 'SAMEORIGIN') + self.setHeader('X-XSS-Protection', '1; mode=block') + self.setHeader('X-Content-Type-Options', 'nosniff') if self.isSecure(): self.setHeader('Strict-Transport-Security', 'max-age=31536000; includeSubDomains') -- cgit v1.2.3