Joomla 4 Security HTTP Headers Updated on August 20, 2021 by InMotion Hosting Contributor 2 Minutes, 35 Seconds to Read Learning how to secure Joomla 4 is easier than ever before. With the pre-installed HTTP Headers Joomla plugin, you can add up to ten security HTTP headers to protect your data against next-generation cyber attacks. How to Secure Joomla 4 with HTTP Headers Log into your Joomla 4 administrator dashboard (e.g. https://example.com/administrator).Select System from the sidebar.Under Manage, select Plugins.Search for “System – HTTP Headers” and select it. X-Frame-Options specifies whether or how your website can be embedded in another web app or site using iframes. This will harden Joomla against clickjacking. The options for this header are “DENY” and “SAMEORIGIN” (meaning you can embed your website within itself). This is enabled and set to “SAMEORIGIN” by default. Referrer-Policy can remove sensitive content from the refererr header within URI requests (e.g. password reset URLs). There are nine options in the drop-down menu: empty string – no preferenceno-referrer – no referrer info sentno-referrer-when-downgrade – full URL unless visiting HTTP page from HTTPS page (default behavior when no policy specified)same-origin – only origin (root domain – e.g. example.com instead of example.com/blog) for within the same siteorigin – only originstrict-origin – origin only when security level is the same (e.g. HTTPS to HTTPS)origin-when-cross-origin – full URL for within the same site, but only origin externallystrict-origin-when-cross-origin – full URL within site, only origin when protocol security level is the same (e.g. HTTPS to HTTPS), and no info from HTTPS to HTTPunsafe-url – full URL (not recommended) This is set to “strict-origin-when-cross-origin” by default. Cross-Origin-Opener-Policy (COOP) opens external documents in a separate browsing context group to prevent cross-scripting (XS) attacks. unsafe-none – no protection unless opener has stronger COOP policysame-origin-allow-popups – page keeps references to same-origin popupssame-origin – cross-origin documents are opened in a separate browsing context This is set to “same-origin” by default. The Force HTTP Headers section allows you to add custom HTTP headers. Most notable among the group is Feature-Policy which blocks unnecessary browser features for user privacy (e.g. camera and WebUSB API). This is now superseded by Permissions-Policy. For example, this disables the user’s mic and webcam while allowing full screen for within the site and a Jitsi Meet video conference: microphone=(),camera=(),fullscreen=(self “https://meet/jit/si”) This is set to “interest-cohort=()” by default. Configure HTTP Strict Transport Security (HSTS) from a tab at the top. HSTS forces web browsers to only load your website using secure (HTTPS) connection. Enabling Joomla HSTS works with SSL 301 redirects to protect against HTTP downgrade attacks. You must have a valid SSL certificate on your website while HSTS is enabled. Otherwise, your website will become inaccessible. Configure Content Security Policy (CSP) from the third tab at the top. CSP prevents web browsers from loading anything in the site that’s not specified in the header (e.g. external sources such as BootstrapCDN and YouTube videos). Configure Joomla CSP in more detail under the Force HTTP Headers section. Once done with deciding how to secure Joomla, select Save at the top. You can test your security HTTP headers with online tools such as https://securityheaders.com. Discover how InMotion Hosting's virtual private servers can deliver power and performance for your Joomla site with our reliable Joomla Hosting plans. Share this Article InMotion Hosting Contributor Content Writer InMotion Hosting contributors are highly knowledgeable individuals who create relevant content on new trends and troubleshooting techniques to help you achieve your online goals! More Articles by InMotion Hosting Related Articles How to Use the Free Mini Frontpage Extension for Joomla 4.0 How to Use Bootstrap 5.0 Alerts in Joomla 4.0 Joomla 4.0 2FA with Yubikey Setup Learning About the Menu Interface in Joomla 4.0 Manually Install Joomla 4.0 Easy Joomla 4.0 Backups using Softaculous How to Enable Caching in Joomla 4.0 How to Trash, Unpublish, and Hide Menu Items in Joomla 4.0 How to Add and Remove Menu Items in Joomla 4.0 EmbedChessboard Joomla Plugin