Class ServerHttpSecurity.HeaderSpec.XssProtectionSpec
java.lang.Object
org.springframework.security.config.web.server.ServerHttpSecurity.HeaderSpec.XssProtectionSpec
- Enclosing class:
 - ServerHttpSecurity.HeaderSpec
 
Configures x-xss-protection response header
- 
Method Summary
Modifier and TypeMethodDescriptiondisable()Disables the x-xss-protection response headerSets the value of x-xss-protection header. 
- 
Method Details
- 
disable
Disables the x-xss-protection response header- Returns:
 - the 
ServerHttpSecurity.HeaderSpecto continue configuring 
 - 
headerValue
public ServerHttpSecurity.HeaderSpec headerValue(XXssProtectionServerHttpHeadersWriter.HeaderValue headerValue) Sets the value of x-xss-protection header. OWASP recommends usingXXssProtectionServerHttpHeadersWriter.HeaderValue.DISABLED.- Parameters:
 headerValue- the headerValue- Returns:
 - the 
ServerHttpSecurity.HeaderSpecto continue configuring - Since:
 - 5.8
 
 
 -