SEC-2285: Polish Security Headers Documentation

Explain why (passivity) XML Namespace doesn't enable security headers by
default.
This commit is contained in:
Rob Winch 2013-09-27 16:13:18 -05:00
parent 9bb283044f
commit 06a0ec1a9f
1 changed files with 7 additions and 3 deletions

View File

@ -26,9 +26,13 @@
</listitem>
</itemizedlist></para>
<para>While each of these headers are considered best practice, it should be noted that not all clients
utilize the headers, so additional testing is encouraged. If you are using Spring Security's XML namespace support,
you can easily add all of the default headers with the
<link linkend="nsa-headers">&lt;headers&gt;</link> element with no child elements:</para>
utilize the headers, so additional testing is encouraged. For passivity reasons, if you are using Spring Security's
XML namespace support, you must explicitly enable the security headers. All of the default headers can be easily added
using the <link linkend="nsa-headers">&lt;headers&gt;</link> element with no child elements:</para>
<note>
<para><link xlink:href="https://jira.springsource.org/browse/SEC-2348">SEC-2348</link> is logged to ensure Spring
Security 4.x's XML namespace configuration will enable Security headers by default.</para>
</note>
<programlisting language="xml"><![CDATA[<http>
<!-- ... -->