HTTP header X-XSS-Protection, which is now outdated (replaced by CSP)
and may even cause security vulnerabilities
NetworkPrivate Resource
HTTP header X-XSS-Protection, which is now outdated (replaced by CSP)
and may even cause security vulnerabilities
Min version: 9.0.0Defaults:
enabled mode reportRelationships
2 resources · 2 relationships·Click to select, expand fields to see properties.
Fields (3)
| Field | Type | Description |
|---|---|---|
enabledrequired | int | Whether the header is enabled (Enabled when the header value is set to 1; disabled if set to 0) |
moderequired | string | Mode for XSS filtering |
reportrequired | string | Report endpoint for violations (Chromium only) |