Rails 4预先填充了一些"最佳实践" HTTP标头:
$ http -j "http://127.0.0.1:3000"
(...)
HTTP/1.1 204 No Content
(...)
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-UA-Compatible: chrome=1
X-XSS-Protection: 1; mode=block
如何在Rails 4中更改这些标题?
答案 0 :(得分:4)
要禁用(或更改)该行,请将以下行添加到config/application.rb
:
config.action_dispatch.default_headers = {
'X-Frame-Options' => 'DENY',
'X-UA-Compatible' => 'IE=EmulateIE7'
}