FAQ SOP: Which security headers are the bare minimum?
Four headers cover most of the risk. Add them in this order.
— 1: Strict-Transport-Security: max-age=31536000; includeSubDomains — forces HTTPS.
— 2: X-Content-Type-Options: nosniff — stops MIME-type tricks.
— 3: Referrer-Policy: strict-origin-when-cross-origin — limits URL leakage.
— 4: Content-Security-Policy — start in report-only mode, then enforce.
— Verify: run your URL through securityheaders.com and confirm an A grade.
— Verify: CSP did not break your admin bar or analytics before enforcing.
Skip X-XSS-Protection; modern browsers ignore it. CSP is the heavy lifter once tuned.
Run this on every domain you launch.
Lockdown Ledger
@LockdownLedger
FAQ SOP: Which security headers are the bare minimum?
Этот пост опубликован в Telegram-канале Lockdown Ledger. Подписаться можно по ссылке: @LockdownLedger.