From 0064ddbb8b50e3f4f7185d6f17f4bef9b1e2338d Mon Sep 17 00:00:00 2001 From: Dreytac Date: Mon, 7 Oct 2019 19:14:34 +1000 Subject: [PATCH] Add Nextcloud recommended security options --- nextcloud.subdomain.conf.sample | 3 +++ 1 file changed, 3 insertions(+) diff --git a/nextcloud.subdomain.conf.sample b/nextcloud.subdomain.conf.sample index 6ff353d..df30b4d 100644 --- a/nextcloud.subdomain.conf.sample +++ b/nextcloud.subdomain.conf.sample @@ -21,6 +21,9 @@ server { include /config/nginx/ssl.conf; client_max_body_size 0; + + add_header X-Frame-Options "SAMEORIGIN"; + add_header Strict-Transport-Security "max-age=15552000" always; location / { include /config/nginx/proxy.conf;