Class HeadersConfigurer

java.lang.Object
com.codename1.backend.security.SecurityConfigurer
com.codename1.backend.security.HeadersConfigurer

public final class HeadersConfigurer extends SecurityConfigurer

The security headers a chain puts on its responses. On by default:

X-Content-Type-Options: nosniff
X-XSS-Protection: 0
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
Strict-Transport-Security: max-age=31536000 ; includeSubDomains

The cache headers are left out when the handler set any of the three itself, and the last header is sent only on a response to a request that arrived over TLS this server terminated. A header the handler set is never replaced.

http.headers(headers -> headers
        .frameOptions(frame -> frame.sameOrigin())
        .contentSecurityPolicy(csp -> csp.policyDirectives("default-src 'self'")));