added some README instructions for apache CSP (#6667)
Signed-off-by: Katharina Drexel <katharina.drexel@bfh.ch>
sunflowerbofh committed
Aug 15, 2019 at 14:46 UTC
db2335823c475217718c35510570728023b09814
1 file changed
+10
docs/Running-behind-apache.md
+10
@@ -217,6 +217,16 @@ Specify `Location /` if Netdata is running on dedicated virtual host.
217
218
Note: Changes are applied by reloading or restarting Apache.
219
220
+## Configuration of Content Security Policy
221
+
222
+If you want to enable CSP within your Apache, you should consider some special requirements of the headers. Modify your configuration like that:
223
+
224
+```
225
+ Header always set Content-Security-Policy "default-src http: 'unsafe-inline' 'self' 'unsafe-eval'; script-src http: 'unsafe-inline' 'self' 'unsafe-eval'; style-src http: 'self' 'unsafe-inline'"
226
+```
227
+
228
+Note: Changes are applied by reloading or restarting Apache.
229
+
230
# Netdata configuration
231
232
You might edit `/etc/netdata/netdata.conf` to optimize your setup a bit. For applying these changes you need to restart Netdata.