Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Default X-Xss-Protection header value to "0" #11964

Conversation

Kehrlann
Copy link
Contributor

@Kehrlann Kehrlann commented Oct 6, 2022

Fixes gh-9631

@spring-projects-issues spring-projects-issues added the status: waiting-for-triage An issue we've not yet triaged label Oct 6, 2022
@Kehrlann Kehrlann force-pushed the x-xss-protection-defaults-to-zero branch 2 times, most recently from 16a8953 to db906ac Compare October 6, 2022 12:57
@Kehrlann Kehrlann changed the title Default xssProtection to "0", remove .enabled and .block configuration Default X-Xss-Protection header value to "0" Oct 6, 2022
@Kehrlann Kehrlann marked this pull request as ready for review October 6, 2022 13:10
@Kehrlann Kehrlann force-pushed the x-xss-protection-defaults-to-zero branch from db906ac to a4e8e6f Compare October 7, 2022 09:58
@sjohnr
Copy link
Member

sjohnr commented Oct 10, 2022

Merged via 27059ce

@sjohnr sjohnr closed this Oct 10, 2022
@sjohnr sjohnr added status: duplicate A duplicate of another issue in: web An issue in web modules (web, webmvc) type: enhancement A general enhancement type: breaks-passivity A change that breaks passivity with the previous release and removed status: waiting-for-triage An issue we've not yet triaged labels Oct 10, 2022
@sjohnr sjohnr added this to the 6.0.0-RC1 milestone Oct 10, 2022
@sjohnr sjohnr self-assigned this Oct 10, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
in: web An issue in web modules (web, webmvc) status: duplicate A duplicate of another issue type: breaks-passivity A change that breaks passivity with the previous release type: enhancement A general enhancement
Projects
None yet
Development

Successfully merging this pull request may close these issues.

XSS protection should be set to 0 by default per updated OWASP recommendation
3 participants