Skip to content

Commit 3e51223

Browse files
committed
Improved security settings
1 parent 15ef12f commit 3e51223

2 files changed

Lines changed: 5 additions & 2 deletions

File tree

src/com/maxprograms/remotetm/Constants.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ private Constants() {
1919
}
2020

2121
public static final String VERSION = "5.7.0";
22-
public static final String BUILD = "20231028_1759";
22+
public static final String BUILD = "20231115_1100";
2323

2424
public static final String STATUS = "status";
2525
public static final String OK = "OK";

src/com/maxprograms/remotetm/utils/SecurityFilter.java

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38,8 +38,11 @@ public void doFilter(ServletRequest request, ServletResponse response, FilterCha
3838
res.addHeader("Cache-Control", "no-cache");
3939
res.addHeader("Strict-Transport-Security", "max-age=31536000; includeSubDomains");
4040
res.addHeader("X-Permitted-Cross-Domain-Policies", "master-only");
41-
res.addHeader("Content-Security-Policy", "default-src https: 'self' 'unsafe-inline'");
41+
res.addHeader("Content-Security-Policy", "report-uri https://dev.maxprograms.com");
4242
res.addHeader("Referrer-Policy", "no-referrer-when-downgrade");
43+
res.addHeader("X-Frame-Options", "SAMEORIGIN");
44+
res.addHeader("X-XSS-Protection", "1; mode=block");
45+
res.addHeader("Permissions-Policy", "geolocation=(), camera=(), microphone=()");
4346
res.setCharacterEncoding(StandardCharsets.UTF_8.name());
4447
try {
4548
chain.doFilter(request, response);

0 commit comments

Comments
 (0)