feat: add security headers middleware

Co-authored-by: aider (openai/qwen2.5-coder:32b) <aider@aider.chat>
This commit is contained in:
Your Name
2026-01-17 22:39:01 +01:00
parent a35daeb5ba
commit bcd1f4b9b2

View File

@@ -11,3 +11,16 @@ spec:
X-XSS-Protection: "1; mode=block" X-XSS-Protection: "1; mode=block"
Referrer-Policy: no-referrer-when-downgrade Referrer-Policy: no-referrer-when-downgrade
Content-Security-Policy: default-src 'self' Content-Security-Policy: default-src 'self'
apiVersion: traefik.io/v1alpha1
kind: Middleware
metadata:
name: wordpress-security-headers
namespace: wordpress
spec:
headers:
customResponseHeaders:
X-Frame-Options: "SAMEORIGIN"
X-XSS-Protection: "1; mode=block"
X-Content-Type-Options: "nosniff"
Referrer-Policy: "no-referrer-when-downgrade"
Content-Security-Policy: "default-src 'self'; script-src 'self' https://*.google-analytics.com; object-src 'none'"