We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Most browsers have deprecated support for X-XSS-Protection:
Furthermore implementations can be vulnerable for cross-site leak attacks:
Website owners should use Content-Security-Policy (CSP) without allowing unsafe-inline scripts instead.
Proposal: remove test for X-XSS-Protection
The text was updated successfully, but these errors were encountered:
Clashes with #441.
Sorry, something went wrong.
Ok. Given the above (very little support, possible vulnerabilitty and CSP alternative), I suggest to just remove this test and not make it optional.
Fixed on 3c3a35f
gthess
No branches or pull requests
Most browsers have deprecated support for X-XSS-Protection:
Furthermore implementations can be vulnerable for cross-site leak attacks:
Website owners should use Content-Security-Policy (CSP) without allowing unsafe-inline scripts instead.
Proposal: remove test for X-XSS-Protection
The text was updated successfully, but these errors were encountered: