x-xss-protection
Advanced tools
Changelog
2.0.0 - 2016-04-29
dnsPrefetchControl
middleware is now enabled by defaultframeguard
can no longer be initialized with strings; you must use an objecthpkp
lowercase in documentationhpkp
spec URL in readmesframeguard
header name in readmeChangelog
1.2.0 - 2016-02-29
csp
now has a browserSniff
option to disable all user-agent sniffingframeguard
can now be initialized with optionsnpmignore
file to speed up installs slightlyChangelog
1.1.0 - 2016-01-12
dnsPrefetchControl
middlewarecsp
readme had syntax errorsChangelog
1.0.0 - 2015-12-18
csp
module supports dynamically-generated valuescsp
directives are now under the directives
keyhpkp
's Report-Only
header is now opt-in, not opt-outcrossdomain
middlewarecsp
no longer throws errors when some directives aren't quoted ('self'
, for example)maxage
option in the hpkp
middlewaresafari5
option from csp
moduleunsafe-inline
and unsafe-eval
csp
policies is no longer recursive