Class HeadersConfigurer
java.lang.Object
com.codename1.backend.security.SecurityConfigurer
com.codename1.backend.security.HeadersConfigurer
The security headers a chain puts on its responses. On by default:
X-Content-Type-Options: nosniff
X-XSS-Protection: 0
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
The cache headers are left out when the handler set any of the three itself, and the last header is sent only on a response to a request that arrived over TLS this server terminated. A header the handler set is never replaced.
http.headers(headers -> headers
.frameOptions(frame -> frame.sameOrigin())
.contentSecurityPolicy(csp -> csp.policyDirectives("default-src 'self'")));
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionstatic final classContent-Security-Policy.static final classX-Frame-Options.static final classStrict-Transport-Security.static final classA header that is either sent or not. -
Method Summary
Modifier and TypeMethodDescriptionaddHeaderWriter(HeaderWriter headerWriter) One more writer, run after the built-in ones.cacheControl(Customizer<HeadersConfigurer.Toggle> cacheControlCustomizer) The headers that keep a response out of caches.voidconfigure(HttpSecurity http) Adds this part's filters; nothing by default.contentSecurityPolicy(Customizer<HeadersConfigurer.ContentSecurityPolicyConfig> contentSecurityCustomizer) Content-Security-Policy; not sent unless configured here.contentTypeOptions(Customizer<HeadersConfigurer.Toggle> contentTypeOptionsCustomizer) X-Content-Type-Options: nosniff.Turns every default off, leaving what is configured after this call.frameOptions(Customizer<HeadersConfigurer.FrameOptionsConfig> frameOptionsCustomizer) X-Frame-Options: whether a page may be shown in a frame.httpStrictTransportSecurity(Customizer<HeadersConfigurer.HstsConfig> hstsCustomizer) Strict-Transport-Security.xssProtection(Customizer<HeadersConfigurer.Toggle> xssCustomizer) X-XSS-Protection: 0, which tells an old browser to leave its faulty filter off.Methods inherited from class SecurityConfigurer
disable, getBuilder, init
-
Method Details
-
defaultsDisabled
Turns every default off, leaving what is configured after this call. -
frameOptions
public HeadersConfigurer frameOptions(Customizer<HeadersConfigurer.FrameOptionsConfig> frameOptionsCustomizer) X-Frame-Options: whether a page may be shown in a frame. -
httpStrictTransportSecurity
public HeadersConfigurer httpStrictTransportSecurity(Customizer<HeadersConfigurer.HstsConfig> hstsCustomizer) Strict-Transport-Security. -
contentSecurityPolicy
public HeadersConfigurer contentSecurityPolicy(Customizer<HeadersConfigurer.ContentSecurityPolicyConfig> contentSecurityCustomizer) Content-Security-Policy; not sent unless configured here. -
contentTypeOptions
public HeadersConfigurer contentTypeOptions(Customizer<HeadersConfigurer.Toggle> contentTypeOptionsCustomizer) X-Content-Type-Options: nosniff. -
xssProtection
X-XSS-Protection: 0, which tells an old browser to leave its faulty filter off. -
cacheControl
The headers that keep a response out of caches. -
addHeaderWriter
One more writer, run after the built-in ones. -
configure
Description copied from class:SecurityConfigurerAdds this part's filters; nothing by default.- Overrides:
configurein classSecurityConfigurer
-