closing security gap [ignore guarding change for now]

This commit is contained in:
Thanakorn S
2026-05-07 10:29:14 +07:00
parent a24930f684
commit a75d37e841
13 changed files with 39 additions and 93 deletions
+9
View File
@@ -1,3 +1,12 @@
<?php
// Security headers — emitted before any HTML output.
// X-Content-Type-Options: prevents MIME-sniffing attacks.
header('X-Content-Type-Options: nosniff');
// X-Frame-Options: blocks this page from being embedded in a cross-origin iframe.
header('X-Frame-Options: SAMEORIGIN');
// Referrer-Policy: sends origin only on same-origin; omits on cross-origin navigations.
header('Referrer-Policy: strict-origin-when-cross-origin');
?>
<!DOCTYPE html>
<html lang="en">