"X-Frame-Options":
"X-XSS-Protection":
"X-Content-Type-Options"
"X-Permitted-Cross-Domain-Policies"
"Content-Security-Policy" - this is deprecated in favor of the dedicated CSPFilter.
"Referrer-Policy"
Allows specific headers
Allows specific headers
"X-Content-Type-Options"
"X-Frame-Options":
"X-Permitted-Cross-Domain-Policies"
"Referrer-Policy"
"X-XSS-Protection":
"Content-Security-Policy" - this is deprecated in favor of the dedicated CSPFilter.
"Content-Security-Policy" - this is deprecated in favor of the dedicated CSPFilter.
(Since version 2.7.0) Please use play.filters.csp.CSPFilter
(Since version 2.7.0) Please use play.filters.csp.CSPFilter
A type safe configuration object for setting security headers.
"X-Frame-Options":
"X-XSS-Protection":
"X-Content-Type-Options"
"X-Permitted-Cross-Domain-Policies"
"Content-Security-Policy" - this is deprecated in favor of the dedicated CSPFilter.
"Referrer-Policy"
Allows specific headers