diff options
Diffstat (limited to 'config/initializers/secureheaders.rb')
-rw-r--r-- | config/initializers/secureheaders.rb | 10 |
1 files changed, 10 insertions, 0 deletions
diff --git a/config/initializers/secureheaders.rb b/config/initializers/secureheaders.rb new file mode 100644 index 000000000..6c8ac7fbe --- /dev/null +++ b/config/initializers/secureheaders.rb @@ -0,0 +1,10 @@ +SecureHeaders::Configuration.default do |config| + config.cookies = { + secure: true, + httponly: true, + samesite: { + lax: true + } + } + config.csp = SecureHeaders::OPT_OUT +end |