diff options
| author | Diogo Correia <me@diogotc.com> | 2025-09-01 22:36:10 +0100 |
|---|---|---|
| committer | Diogo Correia <me@diogotc.com> | 2025-09-01 22:36:10 +0100 |
| commit | c1292555085e63c4f31a6ffd5b43ede66297efe7 (patch) | |
| tree | bbb55358d3f6c1183aeb31d6c26bc9d09cfd7770 /pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch | |
| parent | 80f6d365434cb3adc3cf46692e2c7855fb1f6157 (diff) | |
nixos/grocy: don't set X-XSS-Protection anymore
Part of #438800.
The OWASP recommentation[1] is:
> The X-XSS-Protection header has been deprecated by modern browsers
> and its use can introduce additional security issues on the client
> side. As such, it is recommended to set the header as X-XSS-Protection: 0
> in order to disable the XSS Auditor, and not allow it to take the default
> behavior of the browser handling the response. Please use
> Content-Security-Policy instead.
[1] https://owasp.org/www-project-secure-headers/#x-xss-protection
Diffstat (limited to 'pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch')
0 files changed, 0 insertions, 0 deletions
