lib/secure_headers/railtie.rb in secure_headers-3.0.3 vs lib/secure_headers/railtie.rb in secure_headers-3.1.0
- old
+ new
@@ -8,10 +8,10 @@
'X-Content-Type-Options', 'Strict-Transport-Security',
'Content-Security-Policy', 'Content-Security-Policy-Report-Only',
'Public-Key-Pins', 'Public-Key-Pins-Report-Only']
initializer "secure_headers.middleware" do
- Rails.application.config.middleware.use SecureHeaders::Middleware
+ Rails.application.config.middleware.insert_before 0, SecureHeaders::Middleware
end
initializer "secure_headers.action_controller" do
ActiveSupport.on_load(:action_controller) do
include SecureHeaders