pareshddevalia opened a new pull request, #774: URL: https://github.com/apache/atlas/pull/774
Stop sending X-XSS-Protection from default HTTP headers and disable Spring Security's XSS protection header in favor of Content-Security-Policy. ## What changes were proposed in this pull request? 1. One of the headers included is X-XSS-PROTECTION, which is now deprecated and no longer supported by modern browsers. - Remove the X-XSS-PROTECTION response header - Remove related constants (X_XSS_PROTECTION_KEY, X_XSS_PROTECTION_VAL) if no longer referenced - Update tests (including HeadersUtilTest, AtlasSecurityConfigTest) accordingly 2. Expected Outcome - Atlas no longer sends deprecated headers 3. Insights - So if we still do not pass the XSS-Protection header, it will still be created in the response header with a default value: "1; mode=block"" - So we can disable it at the Spring Security level in the AtlasSecurityConfig class: - Solution: By adding .headers().xssProtection().disable(), you are explicitly telling the Spring Security framework. So why we selected disabling X_XXX-Protection is: a] Modern browsers have removed support for X-Xss. b] Also, xss functionality is comprehensively and reliably handled by the Content-Security-Policy (CSP) header. ## How was this patch tested? mvn build -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
