README.md in secure_headers-2.2.1 vs README.md in secure_headers-2.2.2
- old
+ new
@@ -47,10 +47,10 @@
config.x_xss_protection = {:value => 1, :mode => 'block'}
config.x_download_options = 'noopen'
config.x_permitted_cross_domain_policies = 'none'
config.csp = {
:default_src => "https: self",
- :enforce => proc {|controller| contoller.current_user.enforce_csp? }
+ :enforce => proc {|controller| contoller.current_user.enforce_csp? },
:frame_src => "https: http:.twimg.com http://itunes.apple.com",
:img_src => "https:",
:report_uri => '//example.com/uri-directive'
}
config.hpkp = {