12.5. XSS Protection

12.5.1. Add XSS protection headers on Apache
12.5.2. Add XSS protection headers on Nginx

Warning

You are looking at documentation for an older release. Not what you want? See the current release documentation.

Even if the XSS protection is handled in the eXo Platform development, some protections can be added on the server side to protect against external threats. They are essentially based on HTTP headers added to the responses to ask the modern browsers to avoid such attacks.

Additional configuration options can be found on the Content-security-Policy header definition.

Copyright ©. All rights reserved. eXo Platform SAS
blog comments powered byDisqus