RedirectMatch 404 /\.git Header append X-FRAME-OPTIONS "SAMEORIGIN" Header append X-Content-Type-Options "nosniff" Header set X-XSS-Protection "1; mode=block" # Header always append X-Frame-Options SAMEORIGIN Header always set Strict-Transport-Security "max-age=604800; includeSubDomains" Header set X-Content-Type-Options nosniff Header edit Set-Cookie ^(.*)$ $1;SameSite=Strict