# Discourse Docker 中的 Nginx 配置？

**URL:** https://meta.discourse.org/t/nginx-config-in-discourse-docker/217699
**Category:** Self-hosting
**Created:** [2022 年2 月 9 日 19:16 UTC](https://meta.discourse.org/t/nginx-config-in-discourse-docker/217699 "2022-02-09T19:16:03Z")
**Posts on this page:** 1
**Showing post:** 5

<div class="post-metadata">

### Author: ![itsbhanusharma](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/itsbhanusharma/32/180717_2.png) [@itsbhanusharma](https://meta.discourse.org/u/itsbhanusharma)
#### Post date: [2022 年2 月 10 日 09:52 UTC](https://meta.discourse.org/t/nginx-config-in-discourse-docker/217699/5 "2022-02-10T09:52:08Z")

</div>

Discourse 通过设置支持添加 CSP，因此您无需对 nginx 进行任何操作。请参阅：

> [@Mitigate XSS Attacks with Content Security Policy](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243):
>
> bookmark This guide explains how to use Content Security Policy (CSP) to mitigate Cross-Site Scripting (XSS) attacks in Discourse. It covers CSP basics, configuration, and best practices. person_raising_hand Required user level: Administrator Summary Content Security Policy (CSP) is a crucial security feature in Discourse that helps protect against Cross-Site Scripting (XSS) and other injection attacks. This guide covers the basics of CSP, how it’s implemented in Discourse, and how to c…

---

_[View the full topic](https://meta.discourse.org/t/nginx-config-in-discourse-docker/217699)._
