Answer the question
In order to leave comments, you need to log in
Why are X-Content-Type-Options, X-XSS-Protection headers not returned on https?
Hello everybody. I have an nginx server in conjunction with php-fpm. In the nginx config (etc/nginx/nginx.conf) in the http block I wrote:
add_header X-Frame-Options SAMEORIGIN;
add_header X-Content-Type-Options nosniff;
add_header X-XSS-Protection "1;mode=block";
Answer the question
In order to leave comments, you need to log in
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question