Skip to content
Snippets Groups Projects
Commit f2bace20 authored by David Beniamine's avatar David Beniamine
Browse files

Fix Nextcloud headers

parent d1e80bcf
Branches
No related tags found
No related merge requests found
......@@ -75,10 +75,17 @@ services:
- "traefik.http.routers.nextcloud.rule=Host(`${HOST}`)"
- "traefik.http.routers.nextcloud.tls.certresolver=myresolver"
- "traefik.http.routers.nextcloud.entrypoints=web,websecure"
- "traefik.http.routers.nextcloud.middlewares=nextcloud@docker"
- "traefik.http.middlewares.nextcloud.headers.forceSTSHeader=true"
- "traefik.http.middlewares.nextcloud.headers.stsIncludeSubdomains=true"
- "traefik.http.middlewares.nextcloud.headers.stsSeconds=31536000"
- "traefik.http.routers.nextcloud.middlewares=nextcloud-caldav@docker,nextcloud-hardening@docker"
- "traefik.http.middlewares.nextcloud-caldav.redirectregex.permanent=true"
- "traefik.http.middlewares.nextcloud-caldav.redirectregex.regex=^https://(.*)/.well-known/(card|cal)dav"
- "traefik.http.middlewares.nextcloud-caldav.redirectregex.replacement=https://$${1}/remote.php/dav/"
- "traefik.http.middlewares.nextcloud-hardening.headers.sslredirect=true"
- "traefik.http.middlewares.nextcloud-hardening.headers.forceSTSHeader=true"
- "traefik.http.middlewares.nextcloud-hardening.headers.stsIncludeSubdomains=true"
- "traefik.http.middlewares.nextcloud-hardening.headers.stsSeconds=15552000"
- "traefik.http.middlewares.nextcloud-hardening.headers.stsPreload=true"
- "traefik.http.middlewares.nextcloud-hardening.headers.referrerPolicy=no-referrer"
- "traefik.http.middlewares.nextcloud-hardening.headers.customFrameOptionsValue=SAMEORIGIN"
volumes:
document_data:
......
......@@ -48,7 +48,9 @@ http {
listen 80;
# Add headers to serve security related headers
add_header Referrer-Policy "no-referrer" always;
add_header Strict-Transport-Security "max-age=15768000; includeSubDomains; preload;";
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-Content-Type-Options nosniff;
add_header X-XSS-Protection "1; mode=block";
add_header X-Robots-Tag none;
......@@ -65,9 +67,6 @@ http {
error_page 403 /core/templates/403.php;
error_page 404 /core/templates/404.php;
rewrite ^/.well-known/carddav /remote.php/dav/ permanent;
rewrite ^/.well-known/caldav /remote.php/dav/ permanent;
location = /robots.txt {
allow all;
log_not_found off;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment