Skip to content

chore: add ngnix security headers#964

Closed
Agastya18 wants to merge 2 commits intomainfrom
feat/add-security-nginx
Closed

chore: add ngnix security headers#964
Agastya18 wants to merge 2 commits intomainfrom
feat/add-security-nginx

Conversation

@Agastya18
Copy link
Collaborator

@Agastya18 Agastya18 commented Dec 5, 2024

Description

This pull request for issue #939 updates the Nginx configuration to enhance security and allow communication with specific origins. The changes include:
Security Headers: Added headers to prevent MIME type sniffing, clickjacking, and XSS attacks.
Content Security Policy (CSP): Configured to restrict resources to specific trusted domains, including Google Analytics, Google Fonts, and hasadna.org.il.
CORS Configuration: Updated to allow cross-origin requests from specified domains.

screenshots

Screenshot 2024-12-05 at 7 40 38 PM

@Agastya18 Agastya18 requested a review from NoamGaash as a code owner December 5, 2024 14:11
@github-actions
Copy link
Contributor

github-actions bot commented Dec 5, 2024

@NoamGaash NoamGaash changed the title add ngnix security chore: add ngnix security headers Dec 5, 2024
@NoamGaash
Copy link
Member

Thanks!
But seems like the tests are failing when executed on the dockerized version:
image
https://eyes.applitools.com/app/test-results/00000251668441915811/?accountId=ClQJqzT0PkebrsewHfaQEQ__

@NoamGaash NoamGaash closed this Dec 1, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants