Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove x-xss-protection header from default headers in httpapi (SYN-4641) #2997

Merged
merged 2 commits into from
Jan 26, 2023

Conversation

vEpiphyte
Copy link
Contributor

The x-xss-protection header is not supported by most browsers and is a non-standard header ( see https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-XSS-Protection ). This can be added to a service with the https:headers if a user needs it for a given deployment.

@vEpiphyte vEpiphyte added this to the v2.122.0 milestone Jan 25, 2023
@codecov
Copy link

codecov bot commented Jan 25, 2023

Codecov Report

Base: 97.21% // Head: 97.11% // Decreases project coverage by -0.11% ⚠️

Coverage data is based on head (ac7c5b9) compared to base (876f388).
Patch has no changes to coverable lines.

Additional details and impacted files
@@            Coverage Diff             @@
##           master    #2997      +/-   ##
==========================================
- Coverage   97.21%   97.11%   -0.11%     
==========================================
  Files         218      218              
  Lines       43205    43204       -1     
==========================================
- Hits        42003    41957      -46     
- Misses       1202     1247      +45     
Flag Coverage Δ
linux 97.11% <ø> (+<0.01%) ⬆️
linux_replay ?

Flags with carried forward coverage won't be shown. Click here to find out more.

Impacted Files Coverage Δ
synapse/lib/httpapi.py 96.25% <ø> (-0.01%) ⬇️
synapse/tests/utils.py 94.46% <0.00%> (-1.89%) ⬇️
synapse/cortex.py 96.68% <0.00%> (-0.55%) ⬇️
synapse/lib/hiveauth.py 96.01% <0.00%> (-0.48%) ⬇️
synapse/lib/oauth.py 98.68% <0.00%> (-0.44%) ⬇️
synapse/lib/trigger.py 95.01% <0.00%> (-0.39%) ⬇️
synapse/lib/view.py 97.01% <0.00%> (-0.34%) ⬇️
synapse/lib/jsonstor.py 98.32% <0.00%> (-0.24%) ⬇️
synapse/axon.py 98.73% <0.00%> (-0.15%) ⬇️
synapse/lib/layer.py 96.99% <0.00%> (-0.05%) ⬇️

Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.

☔ View full report at Codecov.
📢 Do you have feedback about the report comment? Let us know in this issue.

@vEpiphyte vEpiphyte merged commit 75dd8b5 into master Jan 26, 2023
@vEpiphyte vEpiphyte deleted the feat_xss_removal branch May 1, 2023 20:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants