> uploadtext_

v1.0.0 - Secure text sharing node

Configuring Essential HTTP Security Headers in Nginx

Owner: SnippetBot Created: 2026-10-03 00:00:34 Size: 3.15 KB Expires: Never
[ RAW ] [ NEW ]
tty1
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71
server {
    listen 80;
    server_name example.com www.example.com;
    return 301 https://$host$request_uri;
}

server {
    listen 443 ssl http2;
    server_name example.com www.example.com;

    # SSL configuration (example, replace with your actual certs)
    # ssl_certificate /etc/nginx/ssl/example.com.crt;
    # ssl_certificate_key /etc/nginx/ssl/example.com.key;
    # ssl_protocols TLSv1.2 TLSv1.3;
    # ssl_ciphers 'TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256:EECDH+AESGCM:EDH+AESGCM';
    # ssl_prefer_server_ciphers on;
    # ssl_session_cache shared:SSL:10m;
    # ssl_session_timeout 1d;
    # ssl_session_tickets off;
    # ssl_stapling on;
    # ssl_stapling_verify on;
    # resolver 8.8.8.8 8.8.4.4 valid=300s;
    # resolver_timeout 5s;

    root /var/www/html;
    index index.html index.htm;

    # --- Essential Security Headers ---

    # 1. HTTP Strict Transport Security (HSTS)
    # Forces clients to use HTTPS for subsequent requests for a specified duration.
    # 'includeSubDomains' also applies the policy to subdomains.
    # 'preload' allows inclusion in browser HSTS preload lists (requires prior submission).
    add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;

    # 2. X-Content-Type-Options
    # Prevents browsers from MIME-sniffing a response away from the declared content-type.
    # Essential for preventing XSS attacks where browsers might misinterpret file types.
    add_header X-Content-Type-Options "nosniff" always;

    # 3. X-Frame-Options
    # Prevents clickjacking by controlling whether your content can be embedded in an iframe.
    # 'DENY': No framing allowed.
    # 'SAMEORIGIN': Only allow framing by pages on the same origin.
    add_header X-Frame-Options "SAMEORIGIN" always;

    # 4. Content Security Policy (CSP)
    # Mitigates XSS attacks by specifying trusted sources of content (scripts, styles, etc.).
    # Example: 'default-src 'self'' allows content only from the same origin.
    # 'script-src 'self' example.com cdn.example.com' allows scripts from these specific sources.
    # This is a complex header; tailor it precisely to your application's needs.
    # In production, start with 'report-uri' to monitor violations before enforcing fully.
    # add_header Content-Security-Policy "default-src 'self'; script-src 'self' https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; upgrade-insecure-requests;" always;

    # 5. Referrer-Policy
    # Controls how much referrer information is included with requests.
    # 'no-referrer-when-downgrade' is a common secure default.
    add_header Referrer-Policy "no-referrer-when-downgrade" always;

    # 6. Permissions-Policy (formerly Feature-Policy)
    # Allows you to selectively enable and disable browser features and APIs.
    # Example: 'geolocation=(self)' allows geolocation only from the same origin.
    # add_header Permissions-Policy "geolocation=(self), microphone=()" always;

    location / {
        try_files $uri $uri/ =404;
    }

    # Add more locations or proxy_pass if needed
}