summaryrefslogtreecommitdiff
path: root/pkgs/development/python-modules/python-openstackclient
diff options
context:
space:
mode:
authorMaximilian Bosch <maximilian@mbosch.me>2025-08-31 15:22:16 +0200
committerMaximilian Bosch <maximilian@mbosch.me>2025-08-31 15:22:16 +0200
commit409107d2f5f3abbc5ea5f6414902948776e9954d (patch)
tree661f15d1f359ff2625f2983143e0d271585fadc4 /pkgs/development/python-modules/python-openstackclient
parent925e8b8962e95a54b079299bef7480694dfc0a42 (diff)
nixos/grafana: don't set X-XSS-Protection anymore
Part of #438800. The OWASP recommentation[1] is: > The X-XSS-Protection header has been deprecated by modern browsers > and its use can introduce additional security issues on the client > side. As such, it is recommended to set the header as X-XSS-Protection: 0 > in order to disable the XSS Auditor, and not allow it to take the default > behavior of the browser handling the response. Please use > Content-Security-Policy instead. Hence, we turn this off, diverging from the upstream defaults here. An upstream issue has been opened[2]. [1] https://owasp.org/www-project-secure-headers/#x-xss-protection [2] https://github.com/grafana/grafana/issues/110369
Diffstat (limited to 'pkgs/development/python-modules/python-openstackclient')
0 files changed, 0 insertions, 0 deletions