]> Frank Brehm's Git Trees - pixelpark/hiera.git/commitdiff
spk-spar-checker update configs
authorAndreas Gerstenberg <gerstenberg@pixelpark.com>
Thu, 19 Oct 2017 08:25:12 +0000 (10:25 +0200)
committerAndreas Gerstenberg <gerstenberg@pixelpark.com>
Thu, 19 Oct 2017 08:25:12 +0000 (10:25 +0200)
customer/spk-spar-checker/production.yaml
customer/spk-spar-checker/test.yaml

index 46ddfb535a426d23bb6d87ae5dee5766c2815b08..e1ea35916323709611e3c2fac47b76c921421a9d 100644 (file)
@@ -41,6 +41,7 @@ infra::profile::apache::pp_vhosts:
       - 'always set X-Frame-Options "SAMEORIGIN"'
       - 'always set X-Content-Type-Options "nosniff"'
       - 'always set Strict-Transport-Security: "max-age=15768001"'
+      - 'always set Referrer-Policy "origin"'
       - "set Content-Security-Policy \"default-src 'none'; connect-src 'self'; script-src 'self' data: www.google-analytics.com 'sha256-aed8ae7e95bc21fd56a9074f9eedd4db237cf41ebb8ea603d8bf6764f0d23f4c'; style-src 'self' data: https://webfonts.sparkasse.de 'unsafe-inline'; img-src 'self' data: img.vxcdn.com www.google-analytics.com www.verivox.de; font-src 'self' data: https://webfonts.sparkasse.de; child-src 'self'; object-src 'self'; form-action 'self'; report-uri /api/v1/report;\""
 
     aliases:
@@ -163,7 +164,7 @@ infra::profile::apache::pp_vhosts:
               - '.* /404.html [R=404,L]'
 
       - provider: filesmatch
-        path: '\.(ttf|otf|eot|woff)$'
+        path: '\.(ttf|otf|eot|woff|woff2)$'
         headers:
           - 'always set Access-Control-Allow-Origin "*"'
     rewrites:
index b95c29b25355ded031b112420480147dc3cacd9f..030f81c5d6626d5002398468b7233f19c315f0f3 100644 (file)
@@ -39,6 +39,7 @@ infra::profile::apache::pp_vhosts:
       - 'always set X-Frame-Options "SAMEORIGIN"'
       - 'always set X-Content-Type-Options "nosniff"'
       - 'always set Strict-Transport-Security: "max-age=15768001"'
+      - 'always set Referrer-Policy "origin"'
       - "set Content-Security-Policy \"default-src 'none'; connect-src 'self'; script-src 'self' data: www.google-analytics.com 'sha256-aed8ae7e95bc21fd56a9074f9eedd4db237cf41ebb8ea603d8bf6764f0d23f4c'; style-src 'self' data: https://webfonts.sparkasse.de 'unsafe-inline'; img-src 'self' data: img.vxcdn.com www.google-analytics.com www.verivox.de; font-src 'self' data: https://webfonts.sparkasse.de; child-src 'self'; object-src 'self'; form-action 'self'; report-uri /api/v1/report;\""
 
     aliases:
@@ -161,7 +162,7 @@ infra::profile::apache::pp_vhosts:
               - '.* /404.html [R=404,L]'
 
       - provider: filesmatch
-        path: '\.(ttf|otf|eot|woff)$'
+        path: '\.(ttf|otf|eot|woff|woff2)$'
         headers:
           - 'always set Access-Control-Allow-Origin "*"'
     rewrites: