We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
2 parents 35d21e6 + 91076a6 commit 6044a64Copy full SHA for 6044a64
app/entry.server.tsx
@@ -15,5 +15,15 @@ export default async function handleRequest(
15
routerContext,
16
loadContext,
17
);
18
+
19
+ response.headers.set(
20
+ "Strict-Transport-Security",
21
+ "max-age=63072000; includeSubDomains; preload",
22
+ );
23
+ response.headers.set("Referrer-Policy", "strict-origin-when-cross-origin");
24
+ response.headers.set("X-Content-Type-Options", "nosniff");
25
+ response.headers.set("X-Frame-Options", "DENY");
26
+ response.headers.set("X-Permitted-Cross-Domain-Policies", "none");
27
28
return response;
29
}
0 commit comments