Is it possible to add the following security headers to web GUI?
X-Content-Type-Options
X-XSS-Protection
X-Frame-Options
Content-Security-Policy
or as wishlist for future updates :)
Fabian submitted a recently merged PR via: https://github.com/opnsense/core/pull/2212
There's a bit of discussion. It'll be in 18.7 for sure. Right now we are trying to give it a bit of exposure in the beta in order to see if it has issues.
If anything is missing please discuss via GitHub.
Thanks,
Franco
Great, thanks :)