Hi All,
I would like to reach out how do the cors HTTP headers should be configure. We are currently in process of security review and our InfoSec provided us that we need to update and implement HTML5 Security Standards.
Here is our current Header
Here is the recommendation that we need to implement as per our config above.
Note:
If possible can anyone help me how to implement the above things like. sample line as I'm new in such configurations.
Thank you in advance.
I'm interested by this too :)
Any documentation on it?
Hi,
Maybe this post helps.
Regards,
Daniel
Thank you for the link.
Now I'm on process of implementing the fixes. btw another thing was raised.
We need to replace the Cache-Control from private to no-cache. But when adding the Cache-Control in the web config. it only appends the Cache-Control value now its private, no-cache.
I have replied to your other post here.
Nordin