summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMarkus Heiser <markus.heiser@darmarit.de>2024-01-31 08:52:07 +0100
committerMarkus Heiser <markus.heiser@darmarIT.de>2024-01-31 17:23:41 +0100
commitab8e5383fb6021afd690060c7b718dc505e7d30c (patch)
tree8b6a7720c55aee96fa0c12d20c0047bb2bcb9072
parentdca78f920f5c3c3804eb1463bb095af9dae43aa1 (diff)
downloadsearxng-ab8e5383fb6021afd690060c7b718dc505e7d30c.tar.gz
searxng-ab8e5383fb6021afd690060c7b718dc505e7d30c.zip
[mod] remove X-XSS-Protection headers
Deprecated header not used by browsers nowadays[1]: """In modern browsers, X-XSS-Protection has been deprecated in favor of the Content-Security-Policy to disable the use of inline JavaScript. Its use can introduce XSS vulnerabilities in otherwise safe websites. This should not be used unless you need to support older web browsers that don’t yet support CSP. It is thus recommended to set the header as X-XSS-Protection: 0."""[2] [1] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-XSS-Protection [2] https://infosec.mozilla.org/guidelines/web_security#x-xss-protection Closes: https://github.com/searxng/searxng/issues/3171 Signed-off-by: Markus Heiser <markus.heiser@darmarit.de>
-rw-r--r--docs/admin/settings/settings_server.rst1
-rw-r--r--searx/settings.yml1
-rw-r--r--tests/unit/settings/user_settings.yml1
3 files changed, 0 insertions, 3 deletions
diff --git a/docs/admin/settings/settings_server.rst b/docs/admin/settings/settings_server.rst
index b1b3a14f7..daba6d1dd 100644
--- a/docs/admin/settings/settings_server.rst
+++ b/docs/admin/settings/settings_server.rst
@@ -16,7 +16,6 @@
image_proxy: false
default_http_headers:
X-Content-Type-Options : nosniff
- X-XSS-Protection : 1; mode=block
X-Download-Options : noopen
X-Robots-Tag : noindex, nofollow
Referrer-Policy : no-referrer
diff --git a/searx/settings.yml b/searx/settings.yml
index ebd6d5463..8dbd6bc71 100644
--- a/searx/settings.yml
+++ b/searx/settings.yml
@@ -88,7 +88,6 @@ server:
method: "POST"
default_http_headers:
X-Content-Type-Options: nosniff
- X-XSS-Protection: 1; mode=block
X-Download-Options: noopen
X-Robots-Tag: noindex, nofollow
Referrer-Policy: no-referrer
diff --git a/tests/unit/settings/user_settings.yml b/tests/unit/settings/user_settings.yml
index fba8e6133..c4c4d74ef 100644
--- a/tests/unit/settings/user_settings.yml
+++ b/tests/unit/settings/user_settings.yml
@@ -19,7 +19,6 @@ server:
method: "POST"
default_http_headers:
X-Content-Type-Options: nosniff
- X-XSS-Protection: 1; mode=block
X-Download-Options: noopen
X-Robots-Tag: noindex, nofollow
Referrer-Policy: no-referrer