Add X-XSS-Protection and X-Content-Type-Options

pull/186/head
Omar Roth 2018-09-05 21:51:40 -05:00
rodzic e590d39aa9
commit e6d2166bac
1 zmienionych plików z 3 dodań i 0 usunięć

Wyświetl plik

@ -106,6 +106,9 @@ spawn do
end end
before_all do |env| before_all do |env|
env.response.headers["X-XSS-Protection"] = "1; mode=block;"
env.response.headers["X-Content-Type-Options"] = "nosniff"
if env.request.cookies.has_key? "SID" if env.request.cookies.has_key? "SID"
headers = HTTP::Headers.new headers = HTTP::Headers.new
headers["Cookie"] = env.request.headers["Cookie"] headers["Cookie"] = env.request.headers["Cookie"]