Santandersecurityresearch/DrHeader

Change default policy value for X-XSS-Protection header

Closed this issue · 0 comments

As per current OWASP recommendations, I suggest we change the value enforced by default policy for 'X-XSS-Protection' header to '0'.

https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.md#x-xss-protection-header