Rails 4预先填充了一些“最佳实践”HTTP头:
$ http -j "http://127.0.0.1:3000"
(...)
HTTP/1.1 204 No Content
(...)
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-UA-Compatible: chrome=1
X-XSS-Protection: 1; mode=block如何在Rails 4中更改这些头文件?
发布于 2013-03-28 03:48:56
要禁用(或更改)该功能,请将以下行添加到config/application.rb中
config.action_dispatch.default_headers = {
'X-Frame-Options' => 'DENY',
'X-UA-Compatible' => 'IE=EmulateIE7'
}https://stackoverflow.com/questions/15668096
复制相似问题