Security Headers in htaccess Don't Work
We have an issue on our server when our Security Headers are not working. We added the following to our htaccess file after installing Craft CMS: 
Header always set XXssProtection "1; mode=block"
Header always set XContentTypeOptions "nosniff"
Header always append XFrameOptions ALLOWALL
Header always set StrictTransportSecurity "maxage=31536000"
Header always set ReferrerPolicy noreferrer
These settings worked on our previous CMS which was completely developed in house. We have recently upgraded our server to PHP 7 and Apache 2.4. We have been using https://securityheaders.io to check our results.
Any help trying to get this to work would be really appreciated.
I'm assuming mod_headers is installed & active? Otherwhise I can't say why the .htaccess rules are not applied (devOps is not my forte) but you could set them through the twig template.
I'm assuming mod_headers is installed & active? Otherwhise I can't say why the .htaccess rules are not applied (devOps is not my forte) but you could set them through the twig template.
See here for the tag to use. Basically it comes down to something like this (untested):
{% header 'XXssProtection "1; mode=block"' %}
{% header 'XContentTypeOptions "nosniff' %}
{% header 'XFrameOptions ALLOWALL' %}
{% header 'StrictTransportSecurity "maxage=31536000"' %}
{% header 'ReferrerPolicy noreferrer' %}
You can make those in a block and just include the block on all the relevant pages.
20170717 13:30:54