diff options
author | Rafael Mendonça França <rafaelmfranca@gmail.com> | 2012-08-18 15:36:32 -0700 |
---|---|---|
committer | Rafael Mendonça França <rafaelmfranca@gmail.com> | 2012-08-18 15:36:32 -0700 |
commit | af26adcffbf97e8f7abdd63d0a4d501c70250a09 (patch) | |
tree | c287546075524fa619e965de5ca315fd654ebf7e /actionpack/lib | |
parent | db78e58294c5e4ee6fb960c79f882c80b22afbcf (diff) | |
parent | 4848bf321b34cc06990bf6e3e10cbadaf992bc37 (diff) | |
download | rails-af26adcffbf97e8f7abdd63d0a4d501c70250a09.tar.gz rails-af26adcffbf97e8f7abdd63d0a4d501c70250a09.tar.bz2 rails-af26adcffbf97e8f7abdd63d0a4d501c70250a09.zip |
Merge pull request #7390 from aantix/add_x_content_type_options_to_default_headers
Added X-Content-Type-Options to the header defaults.
Diffstat (limited to 'actionpack/lib')
-rw-r--r-- | actionpack/lib/action_dispatch/railtie.rb | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/actionpack/lib/action_dispatch/railtie.rb b/actionpack/lib/action_dispatch/railtie.rb index 0dcf1fc4fe..5aad8dd23a 100644 --- a/actionpack/lib/action_dispatch/railtie.rb +++ b/actionpack/lib/action_dispatch/railtie.rb @@ -21,7 +21,8 @@ module ActionDispatch config.action_dispatch.default_headers = { 'X-Frame-Options' => 'SAMEORIGIN', - 'X-XSS-Protection' => '1; mode=block' + 'X-XSS-Protection' => '1; mode=block', + 'X-Content-Type-Options' => 'nosniff' } initializer "action_dispatch.configure" do |app| |