Commit cdfb064e authored by tom's avatar tom

more security headers

parent b6380f6f
...@@ -12,6 +12,18 @@ async function headers() { ...@@ -12,6 +12,18 @@ async function headers() {
key: 'X-Content-Type-Options', key: 'X-Content-Type-Options',
value: 'nosniff', value: 'nosniff',
}, },
{
key: 'X-XSS-Protection',
value: '1; mode=block',
},
{
key: 'X-DNS-Prefetch-Control',
value: 'on',
},
{
key: 'Cross-Origin-Opener-Policy',
value: 'same-origin',
},
], ],
}, },
]; ];
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment