From 301e5cca9cd670aacfca1c9df0babfd6c37e1bf9 Mon Sep 17 00:00:00 2001 From: Kerstin Humm Date: Tue, 9 Sep 2025 14:26:02 +0200 Subject: [PATCH] nixos/canaille: remove HTTP header X-XSS-Protection Addresses https://github.com/NixOS/nixpkgs/issues/438800 --- nixos/modules/services/security/canaille.nix | 1 - 1 file changed, 1 deletion(-) diff --git a/nixos/modules/services/security/canaille.nix b/nixos/modules/services/security/canaille.nix index c550e955adb7..cda274012743 100644 --- a/nixos/modules/services/security/canaille.nix +++ b/nixos/modules/services/security/canaille.nix @@ -349,7 +349,6 @@ in add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always; add_header X-Frame-Options "SAMEORIGIN" always; - add_header X-XSS-Protection "1; mode=block" always; add_header X-Content-Type-Options "nosniff" always; add_header Referrer-Policy "same-origin" always; '';