Scan your installation using https://securityheaders.com/.
There are a number of headers which we suggest to enable:
X-Frame-Options: SAMEORIGINX-Content-Type-Options: nosniffX-XSS-Protection: 1; mode=blockReferrer-Policy: strict-origin-when-cross-originStrict-Transport-Security: max-age=31536000Content-Security-Policy: upgrade-insecure-requestsX-Frame-Options, X-Content-Type-Options, X-XSS-Protection in modern browsers. All content loaded by SupportPro is served from your servers so the majority of policy directives should be set to self. script-src and style-src need to permit unsafe-inline as at this time our templates have a lot of inline JavaScript and CSS without nonces.Please consult your web server documentation for steps on how to configure these headers.
Article Number: 181
Author: Jul 18, 2024
Last Updated: Jul 18, 2024
Online URL: https://docs.supportpro.vn/article/configure-http-headers-181.html