Warm tip: This article is reproduced from serverfault.com, please click

其他-X-Frame-Options 标头未设置为 nginx

(其他 - X-Frame-Options header doesnt set to nginx)

发布于 2021-02-12 12:45:45

我的网站在 nginx 服务器上。我添加到/etc/nginx/nginx.conf

add_header X-Frame-Options SAMEORIGIN;
add_header X-Content-Type-Options nosniff;

标题未出现在网站上:

标题未出现在网站上

Questioner
Karina
Viewed
0
Pierre Arnissolle 2021-02-12 21:16:53

我们需要更多关于你的nginx.conf文件的信息,但你可以将此指令添加到你的server块中:

server {
    
    listen 80;
    server_name example.com;

    add_header X-Frame-Options SAMEORIGIN;
    add_header X-Content-Type-Options nosniff;

    # ...
}

可能位于/etc/nginx/sites-enabled/example.com/etc/nginx/conf.d/example.com.conf

如 中的http块所示/etc/nginx/nginx.conf

http {
    
    # ...

    include /etc/nginx/conf.d/*.conf;
    include /etc/nginx/sites-enabled/*;
}