-
Bug
-
Resolution: Done
-
Undefined
-
4.20
-
None
-
Quality / Stability / Reliability
-
False
-
-
None
-
None
-
None
-
None
-
None
-
None
-
In Progress
-
Release Note Not Required
-
N/A
-
None
-
None
-
None
-
None
This is a clone of issue OCPBUGS-61697. The following is the description of the original issue:
—
This is a clone of issue OCPBUGS-60279. The following is the description of the original issue:
—
This is a clone of issue OCPBUGS-60130. The following is the description of the original issue:
—
Description of problem:
We should not set the X-XSS-Protection header. That header is now deprecated and should not be set. See: https://github.com/openshift/console/issues/15344
How reproducible:
Always
Actual results:
X-XSS-Protection is set as: ("X-XSS-Protection", "1; mode=block")
Expected results:
Remove setting the X-XSS-Protection header in totality
Additional info:
https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/X-XSS-Protection
- blocks
-
OCPBUGS-62123 Remove X-XSS-Protection header
-
- Closed
-
- clones
-
OCPBUGS-61697 Remove X-XSS-Protection header
-
- Closed
-
- is blocked by
-
OCPBUGS-61697 Remove X-XSS-Protection header
-
- Closed
-
- is cloned by
-
OCPBUGS-62123 Remove X-XSS-Protection header
-
- Closed
-
- links to