|
9 | 9 | *
|
10 | 10 | * Note: When server is empty string, it will not be added to the response header.
|
11 | 11 | */
|
12 |
| - |
13 | 12 | 'server' => '',
|
14 | 13 |
|
15 | 14 | /**
|
|
19 | 18 | *
|
20 | 19 | * Available Value: 'nosniff'
|
21 | 20 | */
|
22 |
| - |
23 | 21 | 'x-content-type-options' => 'nosniff',
|
24 | 22 |
|
25 | 23 | /**
|
|
29 | 27 | *
|
30 | 28 | * Available Value: 'on', 'off'
|
31 | 29 | */
|
32 |
| - |
33 | 30 | 'x-dns-prefetch-control' => '',
|
34 | 31 |
|
35 | 32 | /**
|
|
39 | 36 | *
|
40 | 37 | * Available Value: 'noopen'
|
41 | 38 | */
|
42 |
| - |
43 | 39 | 'x-download-options' => 'noopen',
|
44 | 40 |
|
45 | 41 | /**
|
46 | 42 | * X-Frame-Options
|
47 | 43 | *
|
48 | 44 | * @see https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options
|
| 45 | + * @deprecated The X-Frame-Options is no longer recommended for use; please use Content-Security-Policy (CSP) instead. |
49 | 46 | *
|
50 | 47 | * Available Value: 'deny', 'sameorigin', 'allow-from <uri>'
|
51 |
| - * |
52 |
| - * @deprecated The X-Frame-Options is no longer recommended for use; please use Content-Security-Policy (CSP) instead. |
53 | 48 | */
|
54 |
| - |
55 | 49 | 'x-frame-options' => 'sameorigin',
|
56 | 50 |
|
57 | 51 | /**
|
|
61 | 55 | *
|
62 | 56 | * Available Value: 'all', 'none', 'master-only', 'by-content-type', 'by-ftp-filename'
|
63 | 57 | */
|
64 |
| - |
65 | 58 | 'x-permitted-cross-domain-policies' => 'none',
|
66 | 59 |
|
67 | 60 | /**
|
|
74 | 67 | *
|
75 | 68 | * @see https://github.com/bepsvpt/secure-headers/issues/58#issuecomment-782332442
|
76 | 69 | */
|
77 |
| - |
78 | 70 | 'x-powered-by' => '',
|
79 | 71 |
|
80 | 72 | /**
|
81 | 73 | * X-XSS-Protection
|
82 | 74 | *
|
83 | 75 | * @see https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-XSS-Protection
|
| 76 | + * @deprecated The X-XSS-Protection is no longer recommended for use; please use Content-Security-Policy (CSP) instead. |
84 | 77 | *
|
85 | 78 | * Available Value: '1', '0', '1; mode=block'
|
86 |
| - * |
87 |
| - * @deprecated The X-XSS-Protection is no longer recommended for use; please use Content-Security-Policy (CSP) instead. |
88 | 79 | */
|
89 |
| - |
90 | 80 | 'x-xss-protection' => '',
|
91 | 81 |
|
92 | 82 | /**
|
|
97 | 87 | * Available Value: 'no-referrer', 'no-referrer-when-downgrade', 'origin', 'origin-when-cross-origin',
|
98 | 88 | * 'same-origin', 'strict-origin', 'strict-origin-when-cross-origin', 'unsafe-url'
|
99 | 89 | */
|
100 |
| - |
101 | 90 | 'referrer-policy' => 'no-referrer',
|
102 | 91 |
|
103 | 92 | /**
|
|
107 | 96 | *
|
108 | 97 | * Available Value: 'unsafe-none', 'require-corp', 'credentialless'
|
109 | 98 | */
|
110 |
| - |
111 | 99 | 'cross-origin-embedder-policy' => 'unsafe-none',
|
112 | 100 |
|
113 | 101 | /**
|
|
117 | 105 | *
|
118 | 106 | * Available Value: 'unsafe-none', 'same-origin-allow-popups', 'same-origin'
|
119 | 107 | */
|
120 |
| - |
121 | 108 | 'cross-origin-opener-policy' => 'unsafe-none',
|
122 | 109 |
|
123 | 110 | /**
|
|
127 | 114 | *
|
128 | 115 | * Available Value: 'same-site', 'same-origin', 'cross-origin'
|
129 | 116 | */
|
130 |
| - |
131 | 117 | 'cross-origin-resource-policy' => 'cross-origin',
|
132 | 118 |
|
133 | 119 | /**
|
134 | 120 | * Clear-Site-Data
|
135 | 121 | *
|
136 | 122 | * @see https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Clear-Site-Data
|
137 | 123 | */
|
138 |
| - |
139 | 124 | 'clear-site-data' => [
|
140 | 125 | 'enable' => false,
|
141 | 126 |
|
|
159 | 144 | *
|
160 | 145 | * Note: Please ensure your website had set up ssl/tls before enable hsts.
|
161 | 146 | */
|
162 |
| - |
163 | 147 | 'hsts' => [
|
164 | 148 | 'enable' => false,
|
165 | 149 |
|
|
177 | 161 | *
|
178 | 162 | * Note: The array key is the endpoint name, and the value is the URL.
|
179 | 163 | */
|
180 |
| - |
181 | 164 | 'reporting' => [
|
182 | 165 | // 'csp' => 'https://example.com/csp-reports',
|
183 | 166 | // 'nel' => 'https://example.com/nel-reports',
|
|
189 | 172 | * @see https://developer.mozilla.org/en-US/docs/Web/HTTP/Network_Error_Logging
|
190 | 173 | * @see https://developer.mozilla.org/en-US/docs/Web/API/Reporting_API
|
191 | 174 | */
|
192 |
| - |
193 | 175 | 'nel' => [
|
194 | 176 | 'enable' => false,
|
195 | 177 |
|
|
209 | 191 | * Expect-CT
|
210 | 192 | *
|
211 | 193 | * @see https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Expect-CT
|
212 |
| - * |
213 | 194 | * @deprecated This feature is no longer recommended.
|
214 | 195 | */
|
215 |
| - |
216 | 196 | 'expect-ct' => [
|
217 | 197 | 'enable' => false,
|
218 | 198 |
|
|
229 | 209 | *
|
230 | 210 | * @see https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Permissions-Policy
|
231 | 211 | */
|
232 |
| - |
233 | 212 | 'permissions-policy' => [
|
234 | 213 | 'enable' => true,
|
235 | 214 |
|
|
635 | 614 | *
|
636 | 615 | * @see https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
|
637 | 616 | */
|
638 |
| - |
639 | 617 | 'csp' => [
|
640 | 618 | 'enable' => true,
|
641 | 619 |
|
|
0 commit comments