From c347236ce9feb8e92e0543e3c51a9bcccf319a9c Mon Sep 17 00:00:00 2001 From: Guillermo Iguaran Date: Fri, 10 Aug 2012 21:11:56 -0500 Subject: Move AD default_headers configurations to railtie ActionDispatch railtie is a better place for config.action_dispatch.default_headers settings, users can continue overriding those settings in their configuration files if needed. --- .../lib/rails/generators/rails/app/templates/config/application.rb | 5 ----- 1 file changed, 5 deletions(-) (limited to 'railties/lib/rails') diff --git a/railties/lib/rails/generators/rails/app/templates/config/application.rb b/railties/lib/rails/generators/rails/app/templates/config/application.rb index a952ff7fb0..b2b760ee7b 100644 --- a/railties/lib/rails/generators/rails/app/templates/config/application.rb +++ b/railties/lib/rails/generators/rails/app/templates/config/application.rb @@ -41,11 +41,6 @@ module <%= app_const_base %> # Configure sensitive parameters which will be filtered from the log file. config.filter_parameters += [:password] - config.action_dispatch.default_headers = { - 'X-Frame-Options' => 'SAMEORIGIN', - 'X-XSS-Protection' => '1; mode=block' - } - # Use SQL instead of Active Record's schema dumper when creating the database. # This is necessary if your schema can't be completely dumped by the schema dumper, # like if you have constraints or database-specific column types. -- cgit v1.2.3