You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
searxng/docs
Markus Heiser ab8e5383fb [mod] remove X-XSS-Protection headers
Deprecated header not used by browsers nowadays[1]:

"""In modern browsers, X-XSS-Protection has been deprecated in favor of the
Content-Security-Policy to disable the use of inline JavaScript. Its use can
introduce XSS vulnerabilities in otherwise safe websites. This should not be
used unless you need to support older web browsers that don’t yet support CSP.
It is thus recommended to set the header as X-XSS-Protection: 0."""[2]

[1] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-XSS-Protection
[2] https://infosec.mozilla.org/guidelines/web_security#x-xss-protection

Closes: https://github.com/searxng/searxng/issues/3171
Signed-off-by: Markus Heiser <markus.heiser@darmarit.de>
8 months ago
..
_themes/searxng [dev-env] upgrade Sphinx-doc 7.2.3 and unpin at v7.1.2 on py3.8 1 year ago
admin [mod] remove X-XSS-Protection headers 8 months ago
build-templates [doc] improve documentation of make targets and ./manage script 1 year ago
dev [mod] presearch: add language & region support 9 months ago
src [mod] isolation of botdetection from the limiter 11 months ago
user [doc] rearranges Settings & Engines docs for better readability 1 year ago
utils [fix] spelling 1 year ago
conf.py [mod] isolation of botdetection from the limiter 11 months ago
index.rst [doc] rearranges Settings & Engines docs for better readability 1 year ago
own-instance.rst [doc] rearranges Settings & Engines docs for better readability 1 year ago