mirror of
https://github.com/scm-manager/scm-manager.git
synced 2025-10-26 08:06:09 +01:00
Set Cross-Origin-Opener-Policy and Cross-Origin-Embedder-Policy headers
This commit is contained in:
committed by
Florian Scholdei
parent
218f669f3d
commit
57f15f3ac4
2
gradle/changelog/cross_origin_header.yaml
Normal file
2
gradle/changelog/cross_origin_header.yaml
Normal file
@@ -0,0 +1,2 @@
|
||||
- type: fixed
|
||||
description: Cross-Origin-Opener-Policy and Cross-Origin-Embedder-Policy headers added to all responses
|
||||
@@ -44,6 +44,8 @@ public class SecurityHeadersFilter extends HttpFilter {
|
||||
if (contextProvider.getStage() != Stage.TESTING) {
|
||||
response.setHeader("X-Frame-Options", "sameorigin");
|
||||
response.setHeader("X-Content-Type-Options", "nosniff");
|
||||
response.setHeader("Cross-Origin-Opener-Policy", "same-origin");
|
||||
response.setHeader("Cross-Origin-Embedder-Policy", "require-corp");
|
||||
response.setHeader("Content-Security-Policy",
|
||||
"form-action 'self'; " +
|
||||
"object-src 'self'; " +
|
||||
|
||||
Reference in New Issue
Block a user