Site logo

Archived topic

Content security headers breaks the site due to issues with default theme code

5 replies · Started by Webmaster on March 10, 2020

Viewing posts 1–6 of 6

Hi there!

I'm trying to implement the following security headers but when testing, the default theme code is not getting along so it breaks the site.

add_header X-Content-Type-Options nosniff;
add_header Content-Security-Policy "default-src 'self';";
*add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload'; *this one works just fine

Can you guys advice?

Thanks!

Hi there,

What about the site breaks, exactly? That code shouldn't have any effect on the theme itself.

Hi Tom,

The whole css, images and fonts break so it loads the content on a white background.

I'm no expert when it comes to this kind of thing. It wouldn't be directly related to the theme, I assume the same thing would happen with any theme. Are you sure the code is valid? Have you checked with your hosting?

Thanks Tom, I found this is related to caching.

Glad you got it sorted :)

This archived topic is closed to new replies.