这个wp-config.php
文件不是放置标题的好地方,但如果您无权访问.htaccess
或者您在Nginx服务器中,不允许修改配置,您可以将其放在主题的functions.php
或插件:
通过WP\\U headers过滤器修改WP headers
function additional_headers( $headers ) { if ( ! is_admin() ) {
$headers[\'Referrer-Policy\'] = \'no-referrer-when-downgrade\';
$headers[\'X-Content-Type-Options\'] = \'nosniff\';
$headers[\'X-XSS-Protection\'] = \'1; mode=block\';
$headers[\'Permissions-Policy\'] = \'geolocation=(self "https://example.com") microphone=() camera=()\';
$headers[\'Content-Security-Policy\'] = \'script-src "self"\';
$headers[\'X-Frame-Options\'] = \'SAMEORIGIN\'; }
return $headers;
}
add_filter( \'wp_headers\', \'additional_securityheaders\' );