Add properties to set additional security headers

Description

Spring Security normally sets the X-XSS-Protection and Strict-Transport-Security HTTP response headers by default. Add system properties to allow an administrator to control setting these headers in GeoServer.

Environment

None

Activity

Fixed

Details

Assignee

Reporter

Fix versions

Components

Priority

Created March 6, 2024 at 4:13 PM
Updated March 25, 2024 at 2:28 PM
Resolved March 25, 2024 at 2:28 PM