{"id":3429,"date":"2020-01-05T23:51:22","date_gmt":"2020-01-05T14:51:22","guid":{"rendered":"https:\/\/tech.akat.info\/?p=3429"},"modified":"2020-01-06T00:34:44","modified_gmt":"2020-01-05T15:34:44","slug":"wordpress-%e3%81%a7-content-security-policy-%e3%82%92%e8%a8%ad%e5%ae%9a%e3%81%97%e3%81%a6%e3%81%bf%e3%81%9f","status":"publish","type":"post","link":"https:\/\/tech.akat.info\/?p=3429","title":{"rendered":"WordPress \u3067 Content Security Policy \u3092\u8a2d\u5b9a\u3057\u3066\u307f\u305f"},"content":{"rendered":"<p>\u6700\u7d42\u7684\u306bNginx\u3067\u4ee5\u4e0b\u306e\u30d8\u30c3\u30c0\u3092\u8a2d\u5b9a\u3057\u305f\u3002<\/p>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\">\r\nadd_header Content-Security-Policy &quot;default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' pagead2.googlesyndication.com googleads.g.doubleclick.net www.google.co.jp apis.google.com www.google-analytics.com adservice.google.co.jp adservice.google.com www.googletagservices.com platform.twitter.com uh.nakanohito.jp cdn.syndication.twimg.com tpc.googlesyndication.com; font-src 'self' fonts.googleapis.com fonts.gstatic.com data:; style-src 'self' 'unsafe-inline' fonts.googleapis.com ajax.googleapis.com platform.twitter.com ton.twimg.com; img-src * data:; child-src www.google.com apis.google.com accounts.google.com googleads.g.doubleclick.net; object-src 'self' pagead2.googlesyndication.com; media-src 'self' pagead2.googlesyndication.com; connect-src 'self' pagead2.googlesyndication.com googleads.g.doubleclick.net uh0.nakanohito.jp; frame-ancestors 'self' googleads.g.doubleclick.net platform.twitter.com syndication.twitter.com www.youtube.com; frame-src 'self' googleads.g.doubleclick.net platform.twitter.com syndication.twitter.com www.youtube.com hatenablog-parts.com; base-uri 'self'; form-action 'self' platform.twitter.com syndication.twitter.com; report-uri https:\/\/{subdomain}.report-uri.com\/r\/d\/csp\/wizard&quot;;\r\n<\/pre>\n<h2>\u8a2d\u5b9a\u3067\u82e6\u52b4\u3057\u305f\u3053\u3068<\/h2>\n<h3>\u30d7\u30e9\u30b0\u30a4\u30f3\u3067\u5bfe\u51e6\u3057\u3088\u3046\u3068\u3057\u305f\u304c\u3046\u307e\u304f\u3044\u304b\u306a\u304b\u3063\u305f<\/h3>\n<p><a href=\"https:\/\/wordpress.org\/plugins\/http-security\/\">HTTP headers to improve web site security<\/a>\u3068\u3044\u3046\u30d7\u30e9\u30b0\u30a4\u30f3\u306b[CSP options]\u30bf\u30d6\u304c\u3042\u3063\u305f\u304creport-uri\u306e\u8a2d\u5b9a\u65b9\u6cd5\u304c\u898b\u3064\u3051\u3089\u308c\u306a\u304b\u3063\u305f\u3002<br \/>\n<a href=\"https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_233727.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_233727-300x257.png\" alt=\"\" width=\"300\" height=\"257\" class=\"alignnone size-medium wp-image-3430\" srcset=\"https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_233727-300x257.png 300w, https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_233727-1024x877.png 1024w, https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_233727-768x658.png 768w, https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_233727-1536x1316.png 1536w, https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_233727.png 1786w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<h3>report-uri\u306e\u66f8\u304d\u65b9\u306b\u82e6\u52b4\u3057\u305f<\/h3>\n<p><a href=\"https:\/\/report-uri.com\/\">Report URI<\/a>\u306b\u767b\u9332\u3057\u3066\u3001<a href=\"https:\/\/docs.report-uri.com\/setup\/csp\/\">Content Security Policy<\/a>\u306breport-uri\u306e\u66f8\u304d\u65b9\u304c\u3042\u308b\u305f\u3081\u3001\u307e\u305a\u306f\u4ee5\u4e0b\u3092\u8a2d\u5b9a\u3057\u305f\u3002<\/p>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\">\r\nadd_header &quot;Content-Security-Policy-Report-Only&quot; &quot;default-src 'none'; form-action 'none'; frame-ancestors 'none'; report-uri https:\/\/{subdomain}.report-uri.com\/r\/d\/csp\/wizard&quot;\r\n<\/pre>\n<p>{subdomain}.report-uri.com\u90e8\u5206\u306b\u3064\u3044\u3066\u306f\u3001\u30a2\u30ab\u30a6\u30f3\u30c8\u3054\u3068\u306b\u7570\u306a\u308b\u305f\u3081[Setup]\u30bf\u30d6\u3092\u78ba\u8a8d\u3059\u308b\u3002<br \/>\n<a href=\"https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_234434.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_234434-300x83.png\" alt=\"\" width=\"300\" height=\"83\" class=\"alignnone size-medium wp-image-3431\" srcset=\"https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_234434-300x83.png 300w, https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_234434-1024x284.png 1024w, https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_234434-768x213.png 768w, https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_234434-1536x426.png 1536w, https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_234434-2048x567.png 2048w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>\u3042\u3068\u306fReport URI\u306e\u30b5\u30a4\u30c8\u3084Chrome\u306a\u3069\u30d6\u30e9\u30a6\u30b6\u306e\u30c7\u30d9\u30ed\u30c3\u30d1\u30fc\u30c4\u30fc\u30eb\u3067\u30a8\u30e9\u30fc\u3092\u5bfe\u51e6\u3057\u3066\u3044\u304f\u3002<br \/>\n<a href=\"https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_040132-1.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_040132-1-300x177.png\" alt=\"\" width=\"300\" height=\"177\" class=\"alignnone size-medium wp-image-3432\" srcset=\"https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_040132-1-300x177.png 300w, https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_040132-1-1024x604.png 1024w, https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_040132-1-768x453.png 768w, https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_040132-1-1536x906.png 1536w, https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_040132-1.png 2024w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\n<a href=\"https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_042007-1.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_042007-1-300x181.png\" alt=\"\" width=\"300\" height=\"181\" class=\"alignnone size-medium wp-image-3433\" srcset=\"https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_042007-1-300x181.png 300w, https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_042007-1-1024x619.png 1024w, https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_042007-1-768x464.png 768w, https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_042007-1-1536x928.png 1536w, https:\/\/tech.akat.info\/wp-content\/uploads\/2020\/01\/2020-01-05_042007-1-2048x1238.png 2048w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<h3>Content-Security-Policy\u30d8\u30c3\u30c0\u306e\u66f8\u304d\u65b9<\/h3>\n<p>\u7d30\u304b\u3044\u66f8\u304d\u65b9\u306a\u3069\u306f\u3001\u4ee5\u4e0b2\u8a18\u4e8b\u3092\u53c2\u8003\u306b\u3057\u305f\u3002<br \/>\n\u30fb<a href=\"https:\/\/a.uotomizu.com\/articles\/content-security-policy-wordpress\/\">Content Security Policy\u3092WordPress\u306b\u5bfe\u5fdc\u3059\u308b\u65b9\u6cd5<\/a><br \/>\n\u30fb<a href=\"https:\/\/gato.intaa.net\/freebsd\/memo\/nginx_settings\">Nginx\u8a2d\u5b9a\u306e\u809d<\/a><\/p>\n<h2>\u305d\u306e\u4ed6\u53c2\u8003\u60c5\u5831<\/h2>\n<p>\u30fb<a href=\"https:\/\/securityheaders.com\/\">Security Headers<\/a>\uff1a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u95a2\u9023\u30d8\u30c3\u30c0\u30c1\u30a7\u30c3\u30af\u30c4\u30fc\u30eb<br \/>\n\u30fb<a href=\"https:\/\/observatory.mozilla.org\/\">Observatory<\/a>\uff1a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30c1\u30a7\u30c3\u30af\u30c4\u30fc\u30eb<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6700\u7d42\u7684\u306bNginx\u3067\u4ee5\u4e0b\u306e\u30d8\u30c3\u30c0\u3092\u8a2d\u5b9a\u3057\u305f\u3002 add_header Content-Security-Policy &quot;default-src &#8216;none&#8217;; script-src &#8216;self&#8217; &#8216;unsafe- [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[98],"tags":[],"_links":{"self":[{"href":"https:\/\/tech.akat.info\/index.php?rest_route=\/wp\/v2\/posts\/3429"}],"collection":[{"href":"https:\/\/tech.akat.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tech.akat.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tech.akat.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/tech.akat.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3429"}],"version-history":[{"count":2,"href":"https:\/\/tech.akat.info\/index.php?rest_route=\/wp\/v2\/posts\/3429\/revisions"}],"predecessor-version":[{"id":3435,"href":"https:\/\/tech.akat.info\/index.php?rest_route=\/wp\/v2\/posts\/3429\/revisions\/3435"}],"wp:attachment":[{"href":"https:\/\/tech.akat.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3429"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tech.akat.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3429"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tech.akat.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3429"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}