aboutsummaryrefslogtreecommitdiffstats
path: root/actionpack/lib/action_dispatch/railtie.rb
diff options
context:
space:
mode:
authorRafael Mendonça França <rafaelmfranca@gmail.com>2012-08-10 20:08:09 -0700
committerRafael Mendonça França <rafaelmfranca@gmail.com>2012-08-10 20:08:09 -0700
commitfeff27d38a1db9d16b06a261bdbe6d0f4683e976 (patch)
tree8e61b0aa0112b42677f07cb4edb5c1088db42b0b /actionpack/lib/action_dispatch/railtie.rb
parentac7e1700f1fd08b50011c256bfa2e382517edb4a (diff)
parent684b6482e4f9d966dfa088b53507847492a023c3 (diff)
downloadrails-feff27d38a1db9d16b06a261bdbe6d0f4683e976.tar.gz
rails-feff27d38a1db9d16b06a261bdbe6d0f4683e976.tar.bz2
rails-feff27d38a1db9d16b06a261bdbe6d0f4683e976.zip
Merge pull request #7329 from guilleiguaran/move-default-headers-ad-railtie
Move AD default_headers configurations to railtie
Diffstat (limited to 'actionpack/lib/action_dispatch/railtie.rb')
-rw-r--r--actionpack/lib/action_dispatch/railtie.rb5
1 files changed, 5 insertions, 0 deletions
diff --git a/actionpack/lib/action_dispatch/railtie.rb b/actionpack/lib/action_dispatch/railtie.rb
index e7f3f07390..0dcf1fc4fe 100644
--- a/actionpack/lib/action_dispatch/railtie.rb
+++ b/actionpack/lib/action_dispatch/railtie.rb
@@ -19,6 +19,11 @@ module ActionDispatch
:verbose => false
}
+ config.action_dispatch.default_headers = {
+ 'X-Frame-Options' => 'SAMEORIGIN',
+ 'X-XSS-Protection' => '1; mode=block'
+ }
+
initializer "action_dispatch.configure" do |app|
ActionDispatch::Http::URL.tld_length = app.config.action_dispatch.tld_length
ActionDispatch::Request.ignore_accept_header = app.config.action_dispatch.ignore_accept_header