Default X-Xss-Protection header value to "0"
Closes gh-9631
This commit is contained in:
committed by
Steve Riesenberg
parent
dcda899c8c
commit
27059ced87
@@ -64,7 +64,7 @@ import org.springframework.util.Assert;
|
||||
* X-Content-Type-Options: nosniff
|
||||
* Strict-Transport-Security: max-age=31536000 ; includeSubDomains
|
||||
* X-Frame-Options: DENY
|
||||
* X-XSS-Protection: 1; mode=block
|
||||
* X-XSS-Protection: 0
|
||||
* </pre>
|
||||
*
|
||||
* @author Rob Winch
|
||||
@@ -73,6 +73,7 @@ import org.springframework.util.Assert;
|
||||
* @author Eddú Meléndez
|
||||
* @author Vedran Pavic
|
||||
* @author Ankur Pathak
|
||||
* @author Daniel Garnier-Moiroux
|
||||
* @since 3.2
|
||||
*/
|
||||
public class HeadersConfigurer<H extends HttpSecurityBuilder<H>>
|
||||
@@ -733,50 +734,6 @@ public class HeadersConfigurer<H extends HttpSecurityBuilder<H>>
|
||||
enable();
|
||||
}
|
||||
|
||||
/**
|
||||
* If false, will not specify the mode as blocked. In this instance, any content
|
||||
* will be attempted to be fixed. If true, the content will be replaced with "#".
|
||||
* @param enabled the new value
|
||||
* @deprecated use
|
||||
* {@link XXssConfig#headerValue(XXssProtectionHeaderWriter.HeaderValue)} instead
|
||||
*/
|
||||
@Deprecated
|
||||
public XXssConfig block(boolean enabled) {
|
||||
this.writer.setBlock(enabled);
|
||||
return this;
|
||||
}
|
||||
|
||||
/**
|
||||
* If true, the header value will contain a value of 1. For example:
|
||||
*
|
||||
* <pre>
|
||||
* X-XSS-Protection: 1
|
||||
* </pre>
|
||||
*
|
||||
* or if {@link XXssProtectionHeaderWriter#setBlock(boolean)} of the given
|
||||
* {@link XXssProtectionHeaderWriter} is true
|
||||
*
|
||||
*
|
||||
* <pre>
|
||||
* X-XSS-Protection: 1; mode=block
|
||||
* </pre>
|
||||
*
|
||||
* If false, will explicitly disable specify that X-XSS-Protection is disabled.
|
||||
* For example:
|
||||
*
|
||||
* <pre>
|
||||
* X-XSS-Protection: 0
|
||||
* </pre>
|
||||
* @param enabled the new value
|
||||
* @deprecated use
|
||||
* {@link XXssConfig#headerValue(XXssProtectionHeaderWriter.HeaderValue)} instead
|
||||
*/
|
||||
@Deprecated
|
||||
public XXssConfig xssProtectionEnabled(boolean enabled) {
|
||||
this.writer.setEnabled(enabled);
|
||||
return this;
|
||||
}
|
||||
|
||||
/**
|
||||
* Sets the value of the X-XSS-PROTECTION header. OWASP recommends using
|
||||
* {@link XXssProtectionHeaderWriter.HeaderValue#DISABLED}.
|
||||
|
||||
@@ -69,10 +69,6 @@ public class HeadersBeanDefinitionParser implements BeanDefinitionParser {
|
||||
|
||||
private static final String ATT_DISABLED = "disabled";
|
||||
|
||||
private static final String ATT_ENABLED = "enabled";
|
||||
|
||||
private static final String ATT_BLOCK = "block";
|
||||
|
||||
private static final String ATT_POLICY = "policy";
|
||||
|
||||
private static final String ATT_STRATEGY = "strategy";
|
||||
@@ -583,20 +579,6 @@ public class HeadersBeanDefinitionParser implements BeanDefinitionParser {
|
||||
BeanDefinitionBuilder builder = BeanDefinitionBuilder.genericBeanDefinition(XXssProtectionHeaderWriter.class);
|
||||
if (xssElt != null) {
|
||||
boolean disabled = "true".equals(getAttribute(xssElt, ATT_DISABLED, "false"));
|
||||
String enabled = xssElt.getAttribute(ATT_ENABLED);
|
||||
if (StringUtils.hasText(enabled)) {
|
||||
if (disabled) {
|
||||
attrNotAllowed(parserContext, ATT_ENABLED, ATT_DISABLED, xssElt);
|
||||
}
|
||||
builder.addPropertyValue("enabled", enabled);
|
||||
}
|
||||
String block = xssElt.getAttribute(ATT_BLOCK);
|
||||
if (StringUtils.hasText(block)) {
|
||||
if (disabled) {
|
||||
attrNotAllowed(parserContext, ATT_BLOCK, ATT_DISABLED, xssElt);
|
||||
}
|
||||
builder.addPropertyValue("block", block);
|
||||
}
|
||||
XXssProtectionHeaderWriter.HeaderValue headerValue = XXssProtectionHeaderWriter.HeaderValue
|
||||
.from(xssElt.getAttribute(ATT_HEADER_VALUE));
|
||||
if (headerValue != null) {
|
||||
|
||||
@@ -1040,7 +1040,7 @@ public class ServerHttpSecurity {
|
||||
* X-Content-Type-Options: nosniff
|
||||
* Strict-Transport-Security: max-age=31536000 ; includeSubDomains
|
||||
* X-Frame-Options: DENY
|
||||
* X-XSS-Protection: 1; mode=block
|
||||
* X-XSS-Protection: 0
|
||||
* </pre>
|
||||
*
|
||||
* such that "Strict-Transport-Security" is only added on secure requests.
|
||||
@@ -1081,7 +1081,7 @@ public class ServerHttpSecurity {
|
||||
* X-Content-Type-Options: nosniff
|
||||
* Strict-Transport-Security: max-age=31536000 ; includeSubDomains
|
||||
* X-Frame-Options: DENY
|
||||
* X-XSS-Protection: 1; mode=block
|
||||
* X-XSS-Protection: 0
|
||||
* </pre>
|
||||
*
|
||||
* such that "Strict-Transport-Security" is only added on secure requests.
|
||||
|
||||
@@ -25,18 +25,12 @@ import org.springframework.security.web.header.writers.XXssProtectionHeaderWrite
|
||||
* idiomatic Kotlin code.
|
||||
*
|
||||
* @author Eleftheria Stein
|
||||
* @author Daniel Garnier-Moiroux
|
||||
* @since 5.3
|
||||
* @property block whether to specify the mode as blocked
|
||||
* @property xssProtectionEnabled if true, the header value will contain a value of 1.
|
||||
* If false, will explicitly disable specify that X-XSS-Protection is disabled.
|
||||
* @property headerValue the value of the X-XSS-Protection header. OWASP recommends [HeaderValue.DISABLED].
|
||||
*/
|
||||
@HeadersSecurityMarker
|
||||
class XssProtectionConfigDsl {
|
||||
@Deprecated("use headerValue instead")
|
||||
var block: Boolean? = null
|
||||
@Deprecated("use headerValue instead")
|
||||
var xssProtectionEnabled: Boolean? = null
|
||||
var headerValue: HeaderValue? = null
|
||||
|
||||
private var disabled = false
|
||||
@@ -50,8 +44,6 @@ class XssProtectionConfigDsl {
|
||||
|
||||
internal fun get(): (HeadersConfigurer<HttpSecurity>.XXssConfig) -> Unit {
|
||||
return { xssProtection ->
|
||||
block?.also { xssProtection.block(block!!) }
|
||||
xssProtectionEnabled?.also { xssProtection.xssProtectionEnabled(xssProtectionEnabled!!) }
|
||||
headerValue?.also { xssProtection.headerValue(headerValue) }
|
||||
|
||||
if (disabled) {
|
||||
|
||||
@@ -1268,13 +1268,7 @@ xss-protection.attlist &=
|
||||
## disable the X-XSS-Protection header. Default is 'false' meaning it is enabled.
|
||||
attribute disabled {xsd:boolean}?
|
||||
xss-protection.attlist &=
|
||||
## specify that XSS Protection should be explicitly enabled or disabled. Default is 'true' meaning it is enabled.
|
||||
attribute enabled {xsd:boolean}?
|
||||
xss-protection.attlist &=
|
||||
## Add mode=block to the header or not, default is on.
|
||||
attribute block {xsd:boolean}?
|
||||
xss-protection.attlist &=
|
||||
## Specify the value for the X-Xss-Protection header. When set, overrides both enabled and block attributes.
|
||||
## Specify the value for the X-Xss-Protection header. Defaults to "0".
|
||||
attribute header-value {"0"|"1"|"1; mode=block"}?
|
||||
|
||||
content-type-options =
|
||||
|
||||
@@ -3553,23 +3553,9 @@
|
||||
</xs:documentation>
|
||||
</xs:annotation>
|
||||
</xs:attribute>
|
||||
<xs:attribute name="enabled" type="xs:boolean">
|
||||
<xs:annotation>
|
||||
<xs:documentation>specify that XSS Protection should be explicitly enabled or disabled. Default is 'true'
|
||||
meaning it is enabled.
|
||||
</xs:documentation>
|
||||
</xs:annotation>
|
||||
</xs:attribute>
|
||||
<xs:attribute name="block" type="xs:boolean">
|
||||
<xs:annotation>
|
||||
<xs:documentation>Add mode=block to the header or not, default is on.
|
||||
</xs:documentation>
|
||||
</xs:annotation>
|
||||
</xs:attribute>
|
||||
<xs:attribute name="header-value">
|
||||
<xs:annotation>
|
||||
<xs:documentation>Specify the value for the X-Xss-Protection header. When set, overrides both enabled and
|
||||
block attributes.
|
||||
<xs:documentation>Specify the value for the X-Xss-Protection header. Defaults to "0".
|
||||
</xs:documentation>
|
||||
</xs:annotation>
|
||||
<xs:simpleType>
|
||||
|
||||
Reference in New Issue
Block a user