Files
grecia/config/initializers
Javi Martín d846fdad39 Use the new default headers
The only change between these headers and the ones sent by Rails 6.1
application is that now the `X-XSS-Protection` header is set to zero. As
mentioned in the pull request introducing the change [1]:

> This header has been deprecated and the XSS auditor it triggered has
> been removed from all major modern browsers (in favour of Content
> Security Policy) that implemented this header to begin with (Firefox
> never did).

[1] Pull request 41769 in https://github.com/rails/rails
2024-04-15 15:39:28 +02:00
..
2021-08-15 01:26:29 +02:00
2023-09-11 23:40:37 +02:00
2020-06-16 13:47:38 +02:00
2019-04-16 17:28:06 +02:00
2023-10-24 19:00:43 +02:00
2023-11-23 18:21:29 +01:00
2024-04-15 15:39:23 +02:00
2017-04-03 12:30:57 +02:00
2015-07-15 13:32:13 +02:00
2023-09-11 23:40:37 +02:00