-
Notifications
You must be signed in to change notification settings - Fork 98
5.2 Headers - Clarify X-Powered-By #272
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Labels
Question
Further information is requested
Comments
+1 to removing this. |
+2 as much as it's nice to see evidence of your handy work... most significant deployments turn it off |
Security by obscurity. |
stuartwdouglas
added a commit
to stuartwdouglas/servlet-api
that referenced
this issue
Sep 13, 2020
Fixes jakartaee#272 Signed-off-by: Stuart Douglas <[email protected]>
stuartwdouglas
added a commit
to stuartwdouglas/servlet-api
that referenced
this issue
Sep 22, 2020
Fixes jakartaee#272 Signed-off-by: Stuart Douglas <[email protected]>
stuartwdouglas
added a commit
to stuartwdouglas/servlet-api
that referenced
this issue
Oct 13, 2020
Fixes jakartaee#272 Signed-off-by: Stuart Douglas <[email protected]>
stuartwdouglas
added a commit
to stuartwdouglas/servlet-api
that referenced
this issue
Oct 13, 2020
Fixes jakartaee#272 Signed-off-by: Stuart Douglas <[email protected]>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
In section 5.2 it states the following:
I'd like to propose that we either remove the recommendation of adding the X-Powered-By header or at the very least clearly document that it should be disabled by default.
Often times this header is flagged as an information disclosure by security tools. I'd also like to
ensure that there are no compliance tests that check for this header as the spec only says it is
recommended rather than required.
My personal choice would be to remove this totally.
The text was updated successfully, but these errors were encountered: