core
core copied to clipboard
[SecurityCenter] Set additional security headers
- Set
X-Content-Type-Optionsby default tonosniff. - Set
X-XSS-Protectionby default to1; mode=blockinstead of1. - Set
Content-Security-Policyto a restrictive value (depends on #3711). - Make all configurable similar as
X-Frame-Options(see ClickjackProtectionListener). - https://content-security-policy.com/
- https://dev.to/jszutkowski/applying-content-security-policy-in-symfony-to-reduce-xss-risks-5a4l
Refs #3646