Skip to content

Consider a new middleware for the simple security headers. #10342

@blowdart

Description

@blowdart

Inspired by https://github.com/aspnet/templating/issues/497

  • X-Content-Type
  • X-Frame-Options
  • X-XSS-Protection

But not Content-Security-Policy because that's very app dependent to be on by default, and never ever public-key-pins because that's going away because it sucked.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions