Open hvelarde opened 6 years ago
@plone/framework-team this is ready for review; I don't know if the @plone/security-team needs to take a look at it also.
@plone/testing-team I don't know why the job didn't finish.
@hvelarde it clearly says at the end of the output https://jenkins.plone.org/job/pull-request-5.2/1096/console that there is a timeout limit (set to 180 minutes) and it was reached.
Why it did reach that limit... good question.
thanks! fixing the ATContentTypes test seems easy, but I haven't had time for that neither.
Hence there was no activity for a long time, I propose to close this PR within next two weeks. If you do not feel OK with this, please speak up and provide us a rough schedule.
meanwhile, X-XSS-Protection is not used aymore, now we should use CSP. https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
Could we shape this PR up to current standards? This looks useful and I'm tired of having to set these headers in Varnish.
@Rudd-O Is this something you plan to work on?
refs. https://github.com/plone/Products.CMFPlone/issues/2494