Merge pull request #345 from coheigea/sec_headers

Enable X-XSS-Protection + X-Content-Type-Options headers for the webconsole
This commit is contained in:
Jean-Baptiste Onofré 2019-05-14 07:37:58 +02:00 committed by GitHub
commit 1d51c18713
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 11 additions and 1 deletions

View File

@ -54,6 +54,16 @@
<property name="name" value="X-FRAME-OPTIONS"/>
<property name="value" value="SAMEORIGIN"/>
</bean>
<bean id="header" class="org.eclipse.jetty.rewrite.handler.HeaderPatternRule">
<property name="pattern" value="*"/>
<property name="name" value="X-XSS-Protection"/>
<property name="value" value="1; mode=block"/>
</bean>
<bean id="header" class="org.eclipse.jetty.rewrite.handler.HeaderPatternRule">
<property name="pattern" value="*"/>
<property name="name" value="X-Content-Type-Options"/>
<property name="value" value="nosniff"/>
</bean>
</list>
</property>
</bean>
@ -172,4 +182,4 @@
</bean>
</beans>
</beans>