Skip to content

Commit 4fad9d6

Browse files
OhHeyAlanjc21
authored andcommitted
Correcting X-XSS-Protection Header (NginxProxyManager#136)
* Correcting X-XSS-Protection Header X-XSS-Protection sets the configuration for the cross-site scripting filters built into most browsers. The best configuration is "X-XSS-Protection: 1; mode=block". Was "0" Now "1; mode=block" * Update issue templates
1 parent 9e476e5 commit 4fad9d6

File tree

3 files changed

+57
-1
lines changed

3 files changed

+57
-1
lines changed

.github/ISSUE_TEMPLATE/bug_report.md

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
---
2+
name: Bug report
3+
about: Create a report to help us improve
4+
title: ''
5+
labels: bug
6+
assignees: ''
7+
8+
---
9+
10+
**Checklist**
11+
- Have you pulled and found the error with `jc21/nginx-proxy-manager:latest` docker image?
12+
- Are you sure you're not using someone else's docker image?
13+
- If having problems with Lets Encrypt, have you made absolutely sure your site is accessible from outside of your network?
14+
15+
**Describe the bug**
16+
- A clear and concise description of what the bug is.
17+
- What version of Nginx Proxy Manager is reported on the login page?
18+
19+
**To Reproduce**
20+
Steps to reproduce the behavior:
21+
1. Go to '...'
22+
2. Click on '....'
23+
3. Scroll down to '....'
24+
4. See error
25+
26+
**Expected behavior**
27+
A clear and concise description of what you expected to happen.
28+
29+
**Screenshots**
30+
If applicable, add screenshots to help explain your problem.
31+
32+
**Operating System**
33+
- Please specify if using a Rpi, Mac, orchestration tool or any other setups that might affect the reproduction of this error.
34+
35+
**Additional context**
36+
Add any other context about the problem here, docker version, browser version if applicable to the problem. Too much info is better than too little.
Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
---
2+
name: Feature request
3+
about: Suggest an idea for this project
4+
title: ''
5+
labels: enhancement
6+
assignees: ''
7+
8+
---
9+
10+
**Is your feature request related to a problem? Please describe.**
11+
A clear and concise description of what the problem is. Ex. I'm always frustrated when [...]
12+
13+
**Describe the solution you'd like**
14+
A clear and concise description of what you want to happen.
15+
16+
**Describe alternatives you've considered**
17+
A clear and concise description of any alternative solutions or features you've considered.
18+
19+
**Additional context**
20+
Add any other context or screenshots about the feature request here.

src/backend/app.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ app.use(function (req, res, next) {
4848

4949
res.set({
5050
'Strict-Transport-Security': 'includeSubDomains; max-age=631138519; preload',
51-
'X-XSS-Protection': '0',
51+
'X-XSS-Protection': '1; mode=block',
5252
'X-Content-Type-Options': 'nosniff',
5353
'X-Frame-Options': x_frame_options,
5454
'Cache-Control': 'no-cache, no-store, max-age=0, must-revalidate',

0 commit comments

Comments
 (0)