hyperia-sk/yii2-secure-headers

Disable a string is not possible

Closed this issue · 2 comments

The Docs say:
Each header has a reference link in config file, you should read it if you do not know the header. If you want to disable a string type header, just set to null or empty string.

for example "prefetch-src" is experimental. You cannot remove it, just leave it empty. So this will throw a Browser notice. It would be better to remove it.

Content Security Policy: Unbekannte Direktive 'prefetch-src' kann nicht verarbeitet werden

niciz commented

@kasoft see my pull request #27

Hi everyone,

pull request was merged. @kasoft thank you for your contribution.