Class/Object

play.filters.headers

SecurityHeadersConfig

Related Docs: object SecurityHeadersConfig | package headers

Permalink

case class SecurityHeadersConfig(frameOptions: Option[String] = Some("DENY"), xssProtection: Option[String] = Some("1; mode=block"), contentTypeOptions: Option[String] = Some("nosniff"), permittedCrossDomainPolicies: Option[String] = Some("master-only"), contentSecurityPolicy: Option[String] = None, referrerPolicy: Option[String] = ..., allowActionSpecificHeaders: Boolean = false) extends Product with Serializable

A type safe configuration object for setting security headers.

frameOptions

"X-Frame-Options":

xssProtection

"X-XSS-Protection":

contentTypeOptions

"X-Content-Type-Options"

permittedCrossDomainPolicies

"X-Permitted-Cross-Domain-Policies"

contentSecurityPolicy

"Content-Security-Policy" - this is deprecated in favor of the dedicated CSPFilter.

referrerPolicy

"Referrer-Policy"

allowActionSpecificHeaders

Allows specific headers

Source
SecurityHeadersFilter.scala
Linear Supertypes
Serializable, Serializable, Product, Equals, AnyRef, Any
Ordering
  1. Alphabetic
  2. By Inheritance
Inherited
  1. SecurityHeadersConfig
  2. Serializable
  3. Serializable
  4. Product
  5. Equals
  6. AnyRef
  7. Any
  1. Hide All
  2. Show All
Visibility
  1. Public
  2. All

Instance Constructors

  1. new SecurityHeadersConfig()

    Permalink
  2. new SecurityHeadersConfig(frameOptions: Option[String] = Some("DENY"), xssProtection: Option[String] = Some("1; mode=block"), contentTypeOptions: Option[String] = Some("nosniff"), permittedCrossDomainPolicies: Option[String] = Some("master-only"), contentSecurityPolicy: Option[String] = None, referrerPolicy: Option[String] = ..., allowActionSpecificHeaders: Boolean = false)

    Permalink

    frameOptions

    "X-Frame-Options":

    xssProtection

    "X-XSS-Protection":

    contentTypeOptions

    "X-Content-Type-Options"

    permittedCrossDomainPolicies

    "X-Permitted-Cross-Domain-Policies"

    contentSecurityPolicy

    "Content-Security-Policy" - this is deprecated in favor of the dedicated CSPFilter.

    referrerPolicy

    "Referrer-Policy"

    allowActionSpecificHeaders

    Allows specific headers

Value Members

  1. final def !=(arg0: Any): Boolean

    Permalink
    Definition Classes
    AnyRef → Any
  2. final def ##(): Int

    Permalink
    Definition Classes
    AnyRef → Any
  3. final def ==(arg0: Any): Boolean

    Permalink
    Definition Classes
    AnyRef → Any
  4. val allowActionSpecificHeaders: Boolean

    Permalink

    Allows specific headers

  5. final def asInstanceOf[T0]: T0

    Permalink
    Definition Classes
    Any
  6. def clone(): AnyRef

    Permalink
    Attributes
    protected[java.lang]
    Definition Classes
    AnyRef
    Annotations
    @throws( ... )
  7. val contentTypeOptions: Option[String]

    Permalink

    "X-Content-Type-Options"

  8. final def eq(arg0: AnyRef): Boolean

    Permalink
    Definition Classes
    AnyRef
  9. def finalize(): Unit

    Permalink
    Attributes
    protected[java.lang]
    Definition Classes
    AnyRef
    Annotations
    @throws( classOf[java.lang.Throwable] )
  10. val frameOptions: Option[String]

    Permalink

    "X-Frame-Options":

  11. final def getClass(): Class[_]

    Permalink
    Definition Classes
    AnyRef → Any
  12. final def isInstanceOf[T0]: Boolean

    Permalink
    Definition Classes
    Any
  13. final def ne(arg0: AnyRef): Boolean

    Permalink
    Definition Classes
    AnyRef
  14. final def notify(): Unit

    Permalink
    Definition Classes
    AnyRef
  15. final def notifyAll(): Unit

    Permalink
    Definition Classes
    AnyRef
  16. val permittedCrossDomainPolicies: Option[String]

    Permalink

    "X-Permitted-Cross-Domain-Policies"

  17. val referrerPolicy: Option[String]

    Permalink

    "Referrer-Policy"

  18. final def synchronized[T0](arg0: ⇒ T0): T0

    Permalink
    Definition Classes
    AnyRef
  19. final def wait(): Unit

    Permalink
    Definition Classes
    AnyRef
    Annotations
    @throws( ... )
  20. final def wait(arg0: Long, arg1: Int): Unit

    Permalink
    Definition Classes
    AnyRef
    Annotations
    @throws( ... )
  21. final def wait(arg0: Long): Unit

    Permalink
    Definition Classes
    AnyRef
    Annotations
    @throws( ... )
  22. def withContentTypeOptions(contentTypeOptions: Optional[String]): SecurityHeadersConfig

    Permalink
  23. def withFrameOptions(frameOptions: Optional[String]): SecurityHeadersConfig

    Permalink
  24. def withPermittedCrossDomainPolicies(permittedCrossDomainPolicies: Optional[String]): SecurityHeadersConfig

    Permalink
  25. def withReferrerPolicy(referrerPolicy: Optional[String]): SecurityHeadersConfig

    Permalink
  26. def withXssProtection(xssProtection: Optional[String]): SecurityHeadersConfig

    Permalink
  27. val xssProtection: Option[String]

    Permalink

    "X-XSS-Protection":

Deprecated Value Members

  1. val contentSecurityPolicy: Option[String]

    Permalink

    "Content-Security-Policy" - this is deprecated in favor of the dedicated CSPFilter.

    "Content-Security-Policy" - this is deprecated in favor of the dedicated CSPFilter.

    Annotations
    @deprecated
    Deprecated

    (Since version 2.7.0) Please use play.filters.csp.CSPFilter

  2. def withContentSecurityPolicy(contentSecurityPolicy: Optional[String]): SecurityHeadersConfig

    Permalink
    Annotations
    @deprecated
    Deprecated

    (Since version 2.7.0) Please use play.filters.csp.CSPFilter

Inherited from Serializable

Inherited from Serializable

Inherited from Product

Inherited from Equals

Inherited from AnyRef

Inherited from Any

Ungrouped