nixos/grafana: don't set X-XSS-Protection anymore (#438903)

This commit is contained in:
dotlambda
2025-09-01 10:40:34 -07:00
committed by GitHub
@@ -985,10 +985,13 @@ in
x_xss_protection = mkOption {
description = ''
Set to `false` to disable the `X-XSS-Protection` header,
Set to `true` to enable the `X-XSS-Protection` header,
which tells browsers to stop pages from loading when they detect reflected cross-site scripting (XSS) attacks.
__Note:__ this is the default in Grafana, it's turned off here
since it's [recommended to not use this header anymore](https://owasp.org/www-project-secure-headers/#x-xss-protection).
'';
default = true;
default = false;
type = types.bool;
};