aboutsummaryrefslogtreecommitdiffstats
path: root/view/cs/htconfig.tpl
diff options
context:
space:
mode:
Diffstat (limited to 'view/cs/htconfig.tpl')
-rw-r--r--view/cs/htconfig.tpl9
1 files changed, 9 insertions, 0 deletions
diff --git a/view/cs/htconfig.tpl b/view/cs/htconfig.tpl
index 8f26ec7b0..b809aebdf 100644
--- a/view/cs/htconfig.tpl
+++ b/view/cs/htconfig.tpl
@@ -36,6 +36,15 @@ $a->config['system']['baseurl'] = '{{$siteurl}}';
$a->config['system']['sitename'] = "Hubzilla";
$a->config['system']['location_hash'] = '{{$site_id}}';
+// These lines set additional security headers to be sent with all responses
+// You may wish to set transport_security_header to 0 if your server already sends
+// this header. content_security_policy may need to be disabled if you wish to
+// run the piwik analytics plugin or include other offsite resources on a page
+
+$a->config['system']['transport_security_header'] = 1;
+$a->config['system']['content_security_policy'] = 1;
+
+
// Your choices are REGISTER_OPEN, REGISTER_APPROVE, or REGISTER_CLOSED.
// Be certain to create your own personal account before setting
// REGISTER_CLOSED. 'register_text' (if set) will be displayed prominently on