express icon indicating copy to clipboard operation
express copied to clipboard

X-Powered-By Header Enabled By Default

Open cuevaskoch opened this issue 1 year ago • 1 comments

Official documentation recommends that at a minimum we remove the X-Powered-By header when running Express in production. Why is it enabled by default?

Please disable this header in the default configuration.

cuevaskoch avatar May 26 '22 16:05 cuevaskoch

See https://github.com/expressjs/express/pull/2813#issuecomment-159270428 . This is a decision made by the project. I'm not sure when the wording of the website was changed, but we'll get it made to better reflect it.

dougwilson avatar May 26 '22 16:05 dougwilson