Skip to content

Commit

Permalink
[security] remove content type no-sniff from default values (would no…
Browse files Browse the repository at this point in the history
…t work in some environments as local)
  • Loading branch information
ar2rsawseen committed Sep 26, 2016
1 parent 900bc25 commit 78ab8a3
Show file tree
Hide file tree
Showing 2 changed files with 4 additions and 4 deletions.
4 changes: 2 additions & 2 deletions api/api.js
Expand Up @@ -30,8 +30,8 @@ plugins.setConfigs("apps", {
plugins.setConfigs("security", {
login_tries: 3,
login_wait: 5*60,
dashboard_additional_headers: "X-Frame-Options:deny\nX-XSS-Protection:1; mode=block\nX-Content-Type-Options:nosniff\nStrict-Transport-Security:max-age=31536000 ; includeSubDomains",
api_additional_headers: "X-Frame-Options:deny\nX-XSS-Protection:1; mode=block\nX-Content-Type-Options:nosniff"
dashboard_additional_headers: "X-Frame-Options:deny\nX-XSS-Protection:1; mode=block\nStrict-Transport-Security:max-age=31536000 ; includeSubDomains",
api_additional_headers: "X-Frame-Options:deny\nX-XSS-Protection:1; mode=block"
});

plugins.setConfigs('logs', {
Expand Down
4 changes: 2 additions & 2 deletions frontend/express/app.js
Expand Up @@ -67,8 +67,8 @@ plugins.setUserConfigs("frontend", {
plugins.setConfigs("security", {
login_tries: 3,
login_wait: 5*60,
dashboard_additional_headers: "X-Frame-Options:deny\nX-XSS-Protection:1; mode=block\nX-Content-Type-Options:nosniff\nStrict-Transport-Security:max-age=31536000 ; includeSubDomains",
api_additional_headers: "X-Frame-Options:deny\nX-XSS-Protection:1; mode=block\nX-Content-Type-Options:nosniff"
dashboard_additional_headers: "X-Frame-Options:deny\nX-XSS-Protection:1; mode=block\nStrict-Transport-Security:max-age=31536000 ; includeSubDomains",
api_additional_headers: "X-Frame-Options:deny\nX-XSS-Protection:1; mode=block"
});

process.on('uncaughtException', (err) => {
Expand Down

0 comments on commit 78ab8a3

Please sign in to comment.