Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[nelmio/security-bundle] Remove xss_protection config #1344

Merged
merged 1 commit into from
Oct 8, 2024
Merged

Conversation

nicolas-grekas
Copy link
Member

Q A
License MIT
Doc issue/PR -

This header is deprecated, see https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-XSS-Protection
We shouldn't enable it by default.

@symfony-recipes-bot symfony-recipes-bot enabled auto-merge (squash) October 8, 2024 09:41
Copy link

github-actions bot commented Oct 8, 2024

Thanks for the PR 😍

How to test these changes in your application

  1. Define the SYMFONY_ENDPOINT environment variable:

    # On Unix-like (BSD, Linux and macOS)
    export SYMFONY_ENDPOINT=https://raw.githubusercontent.com/symfony/recipes/flex/pull-1344/index.json
    # On Windows
    SET SYMFONY_ENDPOINT=https://raw.githubusercontent.com/symfony/recipes/flex/pull-1344/index.json
  2. Install the package(s) related to this recipe:

    composer req 'symfony/flex:^1.16'
    composer req 'nelmio/security-bundle:^2.4'
  3. Don't forget to unset the SYMFONY_ENDPOINT environment variable when done:

    # On Unix-like (BSD, Linux and macOS)
    unset SYMFONY_ENDPOINT
    # On Windows
    SET SYMFONY_ENDPOINT=

Diff between recipe versions

In order to help with the review stage, I'm in charge of computing the diff between the various versions of patched recipes.
I'm going keep this comment up to date with any updates of the attached patch.

@fabpot fabpot disabled auto-merge October 8, 2024 10:11
@fabpot fabpot merged commit 74769e1 into main Oct 8, 2024
2 checks passed
@fabpot fabpot deleted the nelmio-xss branch October 8, 2024 10:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants