Content Security Policy Configuration
-
Hi, I am having trouble setting up content security policy. I tried getting it to work in functions.php. Then I switched to htaccess. I saw several examples out there. I have the following code in htaccess that works fine:
#Security Header Begin <ifModule mod_headers.c>
Header set Strict-Transport-Security "max-age=31536000" env=HTTPS
Header set X-XSS-Protection "1; mode=block"
Header set X-Content-Type-Options nosniff
Header set X-Frame-Options SAMEORIGIN
Header set Referrer-Policy: no-referrer-when-downgrade
</ifModule>
#Security Header End
If I add the following line:Header set Referrer-Policy: no-referrer-when-downgrade Header set Content-Security-Policy "default-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self';"
I don’t get any syntax errors in the editor but my site will not render anymore. The site after changes just show links and keywords without graphics.#Security Header Begin
<ifModule mod_headers.c>
Header set Strict-Transport-Security "max-age=31536000" env=HTTPS
Header set X-XSS-Protection "1; mode=block"
Header set X-Content-Type-Options nosniff
Header set X-Frame-Options SAMEORIGIN
Header set Referrer-Policy: no-referrer-when-downgrade
Header set Content-Security-Policy "default-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self';"
</ifModule>
#Security Header End
Not sure what I am doing wrong
The topic ‘Content Security Policy Configuration’ is closed to new replies.