Merge pull request #13240 from swordqiu/hotfix/qj-fix-web-security-defects

fix: add header x-xss-protection
This commit is contained in:
Zexi Li
2022-01-20 09:44:28 +08:00
committed by GitHub
+1
View File
@@ -313,6 +313,7 @@ func (app *Application) defaultHandle(w http.ResponseWriter, r *http.Request, ri
params := make(map[string]string)
w.Header().Set("Server", "Yunion AppServer/Go/2018.4")
w.Header().Set("X-Frame-Options", "SAMEORIGIN")
w.Header().Set("X-XSS-Protection", "1; mode=block")
isCors := app.handleCORS(w, r)
handler := app.getRoot(r.Method).Match(segs, params)
if handler != nil {