We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 69f9a3d commit eb151caCopy full SHA for eb151ca
lib/secure_headers/railtie.rb
@@ -3,7 +3,12 @@
3
module SecureHeaders
4
class Railtie < Rails::Engine
5
isolate_namespace ::SecureHeaders if defined? isolate_namespace # rails 3.0
6
- conflicting_headers = ['X-Frame-Options', 'X-XSS-Protection', 'X-Content-Type-Options']
+ conflicting_headers = ['X-Frame-Options', 'X-XSS-Protection', 'X-Content-Type-Options',
7
+ 'X-Permitted-Cross-Domain-Policies', 'X-Download-Options',
8
+ 'X-Content-Type-Options', 'Strict-Transport-Security',
9
+ 'Content-Security-Policy', 'Content-Security-Policy-Report-Only',
10
+ 'X-Permitted-Cross-Domain-Policies']
11
+
12
initializer "secure_headers.action_controller" do
13
ActiveSupport.on_load(:action_controller) do
14
include ::SecureHeaders
0 commit comments