diff --git a/owncloud/nginx.conf b/owncloud/nginx.conf index 0e91932..369d175 100644 --- a/owncloud/nginx.conf +++ b/owncloud/nginx.conf @@ -14,6 +14,10 @@ http { access_log off; error_log /var/log/nginx/error.log error; + add_header Strict-Transport-Security "max-age=15552000; includeSubdomains; prel$ + add_header X-Frame-Options SAMEORIGIN; + add_header X-Content-Type-Options nosniff; + add_header X-XSS-Protection "1; mode=block"; sendfile on; keepalive_timeout 15;