test(e2e): align security header checks with CSP-only XSS defense
This commit is contained in:
@@ -547,7 +547,6 @@ func TestE2E_SecurityHeadersEnhanced(t *testing.T) {
|
|||||||
expectedHeaders := map[string]string{
|
expectedHeaders := map[string]string{
|
||||||
"X-Content-Type-Options": "nosniff",
|
"X-Content-Type-Options": "nosniff",
|
||||||
"X-Frame-Options": "DENY",
|
"X-Frame-Options": "DENY",
|
||||||
"X-XSS-Protection": "1; mode=block",
|
|
||||||
"Referrer-Policy": "strict-origin-when-cross-origin",
|
"Referrer-Policy": "strict-origin-when-cross-origin",
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -707,7 +706,6 @@ func TestE2E_SecurityHeaderCombinations(t *testing.T) {
|
|||||||
requiredHeaders := []string{
|
requiredHeaders := []string{
|
||||||
"X-Content-Type-Options",
|
"X-Content-Type-Options",
|
||||||
"X-Frame-Options",
|
"X-Frame-Options",
|
||||||
"X-XSS-Protection",
|
|
||||||
"Referrer-Policy",
|
"Referrer-Policy",
|
||||||
"Content-Security-Policy",
|
"Content-Security-Policy",
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user