litespeed 不识别 .htaccess 里面的 mod_headers.c 模块
- <IfModule mod_headers.c>
- Header set Cross-Origin-Embedder-Policy "unsafe-none"
- Header set Cross-Origin-Opener-Policy "unsafe-none"
- Header set Cross-Origin-Resource-Policy "cross-origin"
- Header set Content-Security-Policy "report-to default"
- Header set Expect-CT "max-age=2592000;enforce=enforce"
- Header set Feature-Policy "accelerometer 'none';gyroscope 'none';gamepad 'none'"
- Header set Strict-Transport-Security "max-age=2592000; preload"
- Header set X-Download-Options "noopen"
- Header set X-Frame-Options "SAMEORIGIN"
- Header set X-XSS-Protection "1; mode=block"
- </IfModule>
复制代码 需要手动到站点配置里面添加 以下header
- context / {
- location $VH_ROOT/
- allowBrowse 1
- extraHeaders Cross-Origin-Embedder-Policy unsafe-none
- }
- context / {
- location $VH_ROOT/
- allowBrowse 1
- extraHeaders Cross-Origin-Opener-Policy unsafe-none
- }
- context / {
- location $VH_ROOT/
- allowBrowse 1
- extraHeaders Cross-Origin-Resource-Policy cross-origin
- }
- context / {
- location $VH_ROOT/
- allowBrowse 1
- extraHeaders Content-Security-Policy report-to default
- }
- context / {
- location $VH_ROOT/
- allowBrowse 1
- extraHeaders Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
- }
- context / {
- location $VH_ROOT/
- allowBrowse 1
- extraHeaders X-Content-Type-Options nosniff
- }
- context / {
- location $VH_ROOT/
- allowBrowse 1
- extraHeaders X-XSS-Protection 1;mode=block
- }
- context / {
- location $VH_ROOT/
- allowBrowse 1
- extraHeaders X-Frame-Options SAMEORIGIN
- }
- context / {
- location $VH_ROOT/
- allowBrowse 1
- extraHeaders X-Download-Options noopen
- }
- context / {
- location $VH_ROOT/
- allowBrowse 1
- extraHeaders Referrer-Policy strict-origin
- }
- context / {
- location $VH_ROOT/
- allowBrowse 1
- extraHeaders Expect-CT enforce, max-age=2592000
- }
- context / {
- location $VH_ROOT/
- allowBrowse 1
- extraHeaders Feature-Policy geolocation 'self';camera 'none';microphone 'none';encrypted-media 'none';payment 'none';usb 'none'
- }
- context / {
- location $VH_ROOT/
- allowBrowse 1
- extraHeaders Permissions-Policy: "accelerometer=(self),gyroscope=(self), magnetometer=(self)"
- }
- context / {
- location $VH_ROOT/
- allowBrowse 1
- extraHeaders X-Permitted-Cross-Domain-Policies master-only
- }
- #最后一个可以不要
- #context / {
- #location $VH_ROOT/
- #¥allowBrowse 1
- #extraHeaders Content-Security-Policy-Report-Only: default-src 'self'; report-uri default-src
- #}
复制代码
|
|