🛡️OWASP Secure Headers
Generador de Content-Security-Policy & Headers
Bloquea ataques XSS, Clickjacking e inyecciones de scripts maliciosos. Configura directivas CSP visualmente con presets 1-click para Stripe, Google Analytics, Supabase y Vercel.
1. Modo de Operación y Permisos
2. Servicios Terceros (Presets 1-Click)
3. Dominios Personalizados (Opcional)
4. Cabeceras Defensivas Adicionales (OWASP)
Código Generado
// next.config.mjs
/** @type {import('next').NextConfig} */
const nextConfig = {
async headers() {
return [
{
source: '/:path*',
headers: [
{
key: 'Content-Security-Policy',
value: "default-src 'self'; script-src 'self' https://va.vercel-scripts.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: blob:; font-src 'self' https://fonts.gstatic.com; connect-src 'self' https://vitals.vercel-insights.com; frame-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests",
},
{
key: 'Strict-Transport-Security',
value: "max-age=63072000; includeSubDomains; preload",
},
{
key: 'X-Frame-Options',
value: "DENY",
},
{
key: 'X-Content-Type-Options',
value: "nosniff",
},
{
key: 'Referrer-Policy',
value: "strict-origin-when-cross-origin",
},
{
key: 'Permissions-Policy',
value: "camera=(), microphone=(), geolocation=()",
}
],
},
];
},
};
export default nextConfig;
💡 Instrucciones: Pega este bloque en tu archivo next.config.mjs.