lightning-framework / lightning

A simple yet expressive Java web framework.
5 stars 0 forks source link

Add default security headers. #48

Open mschurr opened 7 years ago

mschurr commented 7 years ago

Need to make sure we are setting sensible defaults for security headers:

X_XSS_PROTECTION("X-XSS-Protection"), CONTENT_SECURITY_POLICY("Content-Security-Policy"), STRICT_TRANSPORT_SECURITY("Strict-Transport-Security"), PUBLIC_KEY_PINS("Public-Key-Pins"), X_FRAME_OPTIONS("X-Frame-Options"), X_CONTENT_TYPE_OPTIONS("X-Content-Type-Options"), REFERRER_POLICY("Referrer-Policy");