digitalocean / nginxconfig.io

⚙️ NGINX config generator on steroids 💉
https://do.co/nginxconfig
MIT License
27.42k stars 2.01k forks source link

Why not remove X-XSS-Protection? #455

Open jameskimmel opened 8 months ago

jameskimmel commented 8 months ago

Information

Why not remove X-XSS-Protection in security? Renders some sites unusable, is unnesseary and even can be a security risk according to Mozilla: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-XSS-Protection