Field Manual PHP / Laravel reference
← Security

Secure headers

Response headers can reduce browser-side exposure.

What it is

Response headers can reduce browser-side exposure.

When to use it

Add a policy suited to actual resources and HTTPS deployment.

Syntax

X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
Content-Security-Policy: default-src 'self'; frame-ancestors 'none'

Example

$response = $next($request);
$response->headers->set("X-Content-Type-Options", "nosniff");
$response->headers->set("Referrer-Policy", "same-origin");
return $response;

Common mistakes

CSP must account for inline scripts with nonce/hash; HSTS applies only to HTTPS; headers cannot replace encoding.

Related topics

Browse Security