server { listen 80; server_name example.com www.example.com; return 301 https://$host$request_uri; } server { listen 443 ssl http2; server_name example.com www.example.com; # SSL configuration (example, replace with your actual certs) # ssl_certificate /etc/nginx/ssl/example.com.crt; # ssl_certificate_key /etc/nginx/ssl/example.com.key; # ssl_protocols TLSv1.2 TLSv1.3; # ssl_ciphers 'TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256:EECDH+AESGCM:EDH+AESGCM'; # ssl_prefer_server_ciphers on; # ssl_session_cache shared:SSL:10m; # ssl_session_timeout 1d; # ssl_session_tickets off; # ssl_stapling on; # ssl_stapling_verify on; # resolver 8.8.8.8 8.8.4.4 valid=300s; # resolver_timeout 5s; root /var/www/html; index index.html index.htm; # --- Essential Security Headers --- # 1. HTTP Strict Transport Security (HSTS) # Forces clients to use HTTPS for subsequent requests for a specified duration. # 'includeSubDomains' also applies the policy to subdomains. # 'preload' allows inclusion in browser HSTS preload lists (requires prior submission). add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always; # 2. X-Content-Type-Options # Prevents browsers from MIME-sniffing a response away from the declared content-type. # Essential for preventing XSS attacks where browsers might misinterpret file types. add_header X-Content-Type-Options "nosniff" always; # 3. X-Frame-Options # Prevents clickjacking by controlling whether your content can be embedded in an iframe. # 'DENY': No framing allowed. # 'SAMEORIGIN': Only allow framing by pages on the same origin. add_header X-Frame-Options "SAMEORIGIN" always; # 4. Content Security Policy (CSP) # Mitigates XSS attacks by specifying trusted sources of content (scripts, styles, etc.). # Example: 'default-src 'self'' allows content only from the same origin. # 'script-src 'self' example.com cdn.example.com' allows scripts from these specific sources. # This is a complex header; tailor it precisely to your application's needs. # In production, start with 'report-uri' to monitor violations before enforcing fully. # add_header Content-Security-Policy "default-src 'self'; script-src 'self' https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; upgrade-insecure-requests;" always; # 5. Referrer-Policy # Controls how much referrer information is included with requests. # 'no-referrer-when-downgrade' is a common secure default. add_header Referrer-Policy "no-referrer-when-downgrade" always; # 6. Permissions-Policy (formerly Feature-Policy) # Allows you to selectively enable and disable browser features and APIs. # Example: 'geolocation=(self)' allows geolocation only from the same origin. # add_header Permissions-Policy "geolocation=(self), microphone=()" always; location / { try_files $uri $uri/ =404; } # Add more locations or proxy_pass if needed }