summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMinijackson <minijackson@riseup.net>2022-12-09 15:23:28 +0100
committerMinijackson <minijackson@riseup.net>2022-12-09 15:23:28 +0100
commit14ca3b9ce068e1426c61e150496c6f8ae333fa11 (patch)
tree077172664f4e7d3ec4f5f5304c1377f4e68caa5d
parent80d78293b839e8af3ad0d642ccc834fe1c537df9 (diff)
downloadnixos-config-reborn-14ca3b9ce068e1426c61e150496c6f8ae333fa11.tar.gz
nixos-config-reborn-14ca3b9ce068e1426c61e150496c6f8ae333fa11.zip
nginx: disable default headers
getting errors when overriden by virtual host
-rw-r--r--usecases/server/nginx.nix36
1 files changed, 18 insertions, 18 deletions
diff --git a/usecases/server/nginx.nix b/usecases/server/nginx.nix
index c4c37fd..0e79a35 100644
--- a/usecases/server/nginx.nix
+++ b/usecases/server/nginx.nix
@@ -14,24 +14,24 @@ inputs:
14 recommendedProxySettings = true; 14 recommendedProxySettings = true;
15 recommendedTlsSettings = true; 15 recommendedTlsSettings = true;
16 16
17 commonHttpConfig = '' 17 # commonHttpConfig = ''
18 # Add HSTS header with preloading to HTTPS requests. 18 # # Add HSTS header with preloading to HTTPS requests.
19 # Adding this header to HTTP requests is discouraged 19 # # Adding this header to HTTP requests is discouraged
20 map $scheme $hsts_header { 20 # map $scheme $hsts_header {
21 https "max-age=31536000; includeSubdomains; preload"; 21 # https "max-age=31536000; includeSubdomains; preload";
22 } 22 # }
23 23 #
24 add_header Strict-Transport-Security $hsts_header; 24 # add_header Strict-Transport-Security $hsts_header;
25 25 #
26 add_header 'Referrer-Policy' 'strict-origin-when-cross-origin'; 26 # add_header 'Referrer-Policy' 'strict-origin-when-cross-origin';
27 27 #
28 add_header X-Frame-Options DENY; 28 # add_header X-Frame-Options DENY;
29 29 #
30 add_header X-Content-Type-Options nosniff; 30 # add_header X-Content-Type-Options nosniff;
31 31 #
32 # Better to setup CSP, but nice default nonetheless 32 # # Better to setup CSP, but nice default nonetheless
33 add_header X-XSS-Protection "1; mode=block"; 33 # add_header X-XSS-Protection "1; mode=block";
34 ''; 34 # '';
35 35
36 sslDhparam = config.security.dhparams.params.nginx.path; 36 sslDhparam = config.security.dhparams.params.nginx.path;
37 }; 37 };