Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
@@ -1,7 +1,9 @@
# Ensure node files do not appear
.idea
vscode
package-lock.json
package.json
yarn.lock
node_modules
php-versions.yml
*.tmp
*.tmp
Original file line number Diff line number Diff line change
Expand Up @@ -84,15 +84,15 @@ Header always set X-Frame-Options: "sameorigin"
#
# Referrer policy
#
Header always set Referrer-Policy "no-referrer-when-downgrade"
Header always set Referrer-Policy "strict-origin-when-cross-origin"

#
# Content Security Policy
# UPDATE - September 2020: Commenting this out until we grasp better security requirements
#
#
#Header always set Content-Security-Policy "default-src 'self' http: https: data: blob: 'unsafe-inline'"

#
# Strict-Transport-Security Policy (set HSTS)
#
Header always set Strict-Transport-Security "max-age=15552000; includeSubDomains"
Header always set Strict-Transport-Security "max-age=15552000; includeSubDomains";