pareshddevalia opened a new pull request, #774:
URL: https://github.com/apache/atlas/pull/774

   Stop sending X-XSS-Protection from default HTTP headers and disable Spring 
Security's XSS protection header in favor of Content-Security-Policy.
   
   ## What changes were proposed in this pull request?
   
   1. One of the headers included is X-XSS-PROTECTION, which is now deprecated 
and no longer supported by modern browsers.
   
   -  Remove the X-XSS-PROTECTION response header
   -  Remove related constants (X_XSS_PROTECTION_KEY, X_XSS_PROTECTION_VAL) if 
no longer referenced
   - Update tests (including HeadersUtilTest, AtlasSecurityConfigTest) 
accordingly
   
   2. Expected Outcome
   
   - Atlas no longer sends deprecated headers
   
   3. Insights
   
   - So if we still do not pass the XSS-Protection header, it will still be 
created in the response header with a default value: "1; mode=block""
   - So we can disable it at the Spring Security level in the 
AtlasSecurityConfig class:
   - Solution: By adding .headers().xssProtection().disable(), you are 
explicitly telling the Spring Security framework. So why we selected disabling 
X_XXX-Protection is: a] Modern browsers have removed support for X-Xss. b] 
Also, xss functionality is comprehensively and reliably handled by the 
Content-Security-Policy (CSP) header.
   
   
   ## How was this patch tested?
   
   mvn build


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to