Recommended Values for Security relevant HTTP Headers
Author(s):
Muhammad Akbar
Publish date: Jun 19, 2019
Publish date: Jun 19, 2019
The strict recommended values for security relevant HTTP Headers are provided below. Remember, one size doesn’t fit all.
X-Frame-Options: DENY
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Content-Security-Policy: default-src 'self'; object-src 'none'; base-uri 'none'; upgrade-insecure-requests;
Strict-Transport-Security: max-age=31536000; includeSubDomains