Skip to content

Instantly share code, notes, and snippets.

@vpasquier
Created December 22, 2016 15:34
Show Gist options
  • Save vpasquier/9ceb97b8c0c366b20e723686f43ad487 to your computer and use it in GitHub Desktop.
Save vpasquier/9ceb97b8c0c366b20e723686f43ad487 to your computer and use it in GitHub Desktop.
<component name="org.nuxeo.browser.cache.settings">
<require>org.nuxeo.ecm.platform.web.common.requestcontroller.service.RequestControllerService.defaultContrib</require>
<extension target="org.nuxeo.ecm.platform.web.common.requestcontroller.service.RequestControllerService"
point="responseHeaders">
<header name="X-UA-Compatible">IE=10; IE=11</header>
<header name="Cache-Control">private, max-age=60, must-revalidate</header>
<header name="X-Content-Type-Options">nosniff</header>
<header name="X-XSS-Protection">1; mode=block</header>
<header name="X-Frame-Options">${nuxeo.frame.options:=SAMEORIGIN}</header>
<header name="Content-Security-Policy">default-src *; script-src 'unsafe-inline' 'unsafe-eval' data: *; style-src 'unsafe-inline' *; font-src data: *
</header>
</extension>
</component>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment