diff options
author | Guillermo Iguaran <guilleiguaran@gmail.com> | 2012-08-10 21:11:56 -0500 |
---|---|---|
committer | Guillermo Iguaran <guilleiguaran@gmail.com> | 2012-08-10 21:11:56 -0500 |
commit | c347236ce9feb8e92e0543e3c51a9bcccf319a9c (patch) | |
tree | 9a4cd9adbf6603409a30f281ebdb9e89c38acab4 /actionpack/lib | |
parent | a63fc94aa3689f1e781ac51411ec79a81c011d8a (diff) | |
download | rails-c347236ce9feb8e92e0543e3c51a9bcccf319a9c.tar.gz rails-c347236ce9feb8e92e0543e3c51a9bcccf319a9c.tar.bz2 rails-c347236ce9feb8e92e0543e3c51a9bcccf319a9c.zip |
Move AD default_headers configurations to railtie
ActionDispatch railtie is a better place for
config.action_dispatch.default_headers settings, users can continue
overriding those settings in their configuration files if needed.
Diffstat (limited to 'actionpack/lib')
-rw-r--r-- | actionpack/lib/action_dispatch/railtie.rb | 5 |
1 files changed, 5 insertions, 0 deletions
diff --git a/actionpack/lib/action_dispatch/railtie.rb b/actionpack/lib/action_dispatch/railtie.rb index e7f3f07390..0dcf1fc4fe 100644 --- a/actionpack/lib/action_dispatch/railtie.rb +++ b/actionpack/lib/action_dispatch/railtie.rb @@ -19,6 +19,11 @@ module ActionDispatch :verbose => false } + config.action_dispatch.default_headers = { + 'X-Frame-Options' => 'SAMEORIGIN', + 'X-XSS-Protection' => '1; mode=block' + } + initializer "action_dispatch.configure" do |app| ActionDispatch::Http::URL.tld_length = app.config.action_dispatch.tld_length ActionDispatch::Request.ignore_accept_header = app.config.action_dispatch.ignore_accept_header |