7.576
Bearbeitungen
Änderungen
keine Bearbeitungszusammenfassung
Use the CSP with default-src 'none' or 'self' and without unsafe-eval or unsafe-inline directives. For more information about '''Content Security Policy''', please refer to '''[https://wiki.selfhtml.org/wiki/Sicherheit/Content_Security_Policy SELFHTML>>]'''
'''Example for the header on the start page:'''
'''Configuration of the web server'''
If you can configure your own web server, which is usually not possible in low-budget hosting packages, there is this option via '''changes to .htaccess''':
Header set Content-Security-snapPolicy "default-src 'none'; frame-src 'self'; font-src 'self';img-src 'self' siwecos.de; object-src 'self'; script-src 'self'; style-src 'self';"
Here is an example of an .htaccess file which will set the '''Header Scanner''' to green.
([[Htaccess/EN|.htaccess example]])