Of course i did my research first :) but is there a recommended set of HTTP header items to add to miva sites?
Basic Set of HTTP Headers?
Collapse
X
-
Basic Set of HTTP Headers?
Bruce Golub
Phosphor Media - "Your Success is our Business"
Improve Your Customer Service | Get MORE Customers | Edit CSS/Javascript/HTML Easily | Make Your Site Faster | Get Indexed by Google | Free Modules | Follow Us on Facebook
phosphormedia.comTags: None
-
I'm not sure that these are yet recommended but I think the cache and security headers will become more important.
Headers like x-frames, content-type, xss-protection and csp-directives like default-src and script-src.
-
Yea, that's what got me thinking as a security audit on a site we work on popped up these missing headers. and i assume that i'll need these for the other 40 or so sites we deal with. any other headers folks have found? only want to do this once per site :)Bruce Golub
Phosphor Media - "Your Success is our Business"
Improve Your Customer Service | Get MORE Customers | Edit CSS/Javascript/HTML Easily | Make Your Site Faster | Get Indexed by Google | Free Modules | Follow Us on Facebook
phosphormedia.com
Comment
-
Yeah, right!
only want to do this once per site :)
Realistically the security policy will need to be maintained. It is best to start small and create a report-only policy. Check the logs and then start adding restrictions.
The HTTP Content-Security-Policy-Report-Only response header helps to monitor Content Security Policy (CSP) violations and their effects without enforcing the security policies. This header allows you to test or repair violations before a specific Content-Security-Policy is applied and enforced.
Comment
Comment