lib/secure_headers/railtie.rb in secure_headers-3.2.0 vs lib/secure_headers/railtie.rb in secure_headers-3.3.0
- old
+ new
@@ -5,10 +5,10 @@
isolate_namespace SecureHeaders if defined? isolate_namespace # rails 3.0
conflicting_headers = ['X-Frame-Options', 'X-XSS-Protection',
'X-Permitted-Cross-Domain-Policies', 'X-Download-Options',
'X-Content-Type-Options', 'Strict-Transport-Security',
'Content-Security-Policy', 'Content-Security-Policy-Report-Only',
- 'Public-Key-Pins', 'Public-Key-Pins-Report-Only']
+ 'Public-Key-Pins', 'Public-Key-Pins-Report-Only', 'Referrer-Policy']
initializer "secure_headers.middleware" do
Rails.application.config.middleware.insert_before 0, SecureHeaders::Middleware
end