forked from web/portal
26 lines
976 B
ApacheConf
26 lines
976 B
ApacheConf
# authentication
|
|
AuthType Basic
|
|
AuthName "Geschuetzter Bereich. Zugangsdaten koennen beim AK-IT unbuerokratish angefordert werden."
|
|
AuthUserFile /home/pacs/ecg00/users/portal/doms/my.ecogood.world/.htpasswd
|
|
Require valid-user
|
|
|
|
# CSP Starter Policy: allows images, scripts, AJAX, and CSS from the same origin, and does not allow any other resources to load (eg object, frame, media, etc).
|
|
Header set Content-Security-Policy "default-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self';"
|
|
|
|
# Referrer Policy
|
|
Header always set Referrer-Policy "no-referrer"
|
|
|
|
# redirection depending on the language
|
|
RewriteEngine on
|
|
|
|
RewriteCond %{HTTP:Accept-Language} ^de [NC]
|
|
RewriteRule ^$ https://%{HTTP_HOST}/de [L,R=302]
|
|
|
|
RewriteCond %{HTTP:Accept-Language} ^fr [NC]
|
|
RewriteRule ^$ https://%{HTTP_HOST}/fr [L,R=302]
|
|
|
|
# Fallback for any other language to spanish
|
|
RewriteCond %{HTTP_HOST} my.ecogood.world [NC]
|
|
RewriteRule ^$ https://%{HTTP_HOST}/en [L,R=302]
|
|
|