Skip to content

bagasbayuseto/HeaderSecurity

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 

Repository files navigation

Cara Bikin Website Kamu Kebal Clickjacking dalam 1 Menit.

  1. composer create-project laravel/laravel testing
  2. php artisan make:middleware SecurityHeaders
  3. update bagian middleware

{

public function handle(Request $request, Closure $next): Response
{
    $response = $next($request);
    $response->headers->set('X-Frame-Options', 'SAMEORIGIN');
    $response->headers->set('X-XSS-Protection', '1; mode=block');
    $response->headers->set('X-Content-Type-Options', 'nosniff');
    $response->headers->set('Referrer-Policy', 'no-referrer-when-downgrade');
    $response->headers->set('Strict-Transport-Security', 'max-age=31536000; includeSubDomains');
    $response->headers->set('Content-Security-Policy', "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline';");
    return $response;
}

}

  1. update juga bagian bootsrap/app.php

    ->withMiddleware(function (Middleware $middleware) { $middleware->append(SecurityHeaders::class); })

  2. install cloudfare untuk ujicoba (https) Invoke-WebRequest -Uri "https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-windows-amd64.exe" -OutFile "cloudflared.exe"

  3. running server (php artisan serve)

  4. .\cloudflared.exe tunnel --url http://127.0.0.1:8000

  5. dapatkan link acak saat running tunnel cloudflared

  6. cek header securitymu disini https://securityheaders.com/

About

Taktik 'Satpam Digital' di Balik Website Pemerintah vs Developer.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors