searxng/docs/admin/settings
Markus Heiser ab8e5383fb [mod] remove X-XSS-Protection headers
Deprecated header not used by browsers nowadays[1]:

"""In modern browsers, X-XSS-Protection has been deprecated in favor of the
Content-Security-Policy to disable the use of inline JavaScript. Its use can
introduce XSS vulnerabilities in otherwise safe websites. This should not be
used unless you need to support older web browsers that don’t yet support CSP.
It is thus recommended to set the header as X-XSS-Protection: 0."""[2]

[1] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-XSS-Protection
[2] https://infosec.mozilla.org/guidelines/web_security#x-xss-protection

Closes: https://github.com/searxng/searxng/issues/3171
Signed-off-by: Markus Heiser <markus.heiser@darmarit.de>
2024-01-31 17:23:41 +01:00
..
index.rst
settings.rst
settings_brand.rst
settings_categories_as_tabs.rst
settings_engine.rst
settings_general.rst
settings_outgoing.rst
settings_redis.rst
settings_search.rst [mod] autocomplete.py: add support for mwmbl completions 2023-08-27 17:25:26 +02:00
settings_server.rst [mod] remove X-XSS-Protection headers 2024-01-31 17:23:41 +01:00
settings_ui.rst [mod] add hotkeys option to settings.yml 2023-10-09 18:13:00 +02:00