closing security gap [ignore guarding change for now]
This commit is contained in:
@@ -1,3 +1,12 @@
|
||||
<?php
|
||||
// Security headers — emitted before any HTML output.
|
||||
// X-Content-Type-Options: prevents MIME-sniffing attacks.
|
||||
header('X-Content-Type-Options: nosniff');
|
||||
// X-Frame-Options: blocks this page from being embedded in a cross-origin iframe.
|
||||
header('X-Frame-Options: SAMEORIGIN');
|
||||
// Referrer-Policy: sends origin only on same-origin; omits on cross-origin navigations.
|
||||
header('Referrer-Policy: strict-origin-when-cross-origin');
|
||||
?>
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
|
||||
|
||||
Reference in New Issue
Block a user