Skip to content
This repository was archived by the owner on May 5, 2021. It is now read-only.

Commit 888dc21

Browse files
author
barnabartha
committed
SORMAS-Foundation#2991 - add security headers to vaadin response headers
1 parent ef09d3c commit 888dc21

1 file changed

Lines changed: 5 additions & 0 deletions

File tree

sormas-ui/src/main/java/de/symeda/sormas/ui/SessionFilter.java

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,7 @@
2828
import javax.servlet.ServletResponse;
2929
import javax.servlet.annotation.WebFilter;
3030
import javax.servlet.http.HttpServletRequest;
31+
import javax.servlet.http.HttpServletResponse;
3132
import javax.servlet.http.HttpSession;
3233

3334
import de.symeda.sormas.api.FacadeProvider;
@@ -66,6 +67,10 @@ public void doFilter(ServletRequest request, ServletResponse response, FilterCha
6667
I18nProperties.setUserLanguage(userLanguage);
6768
BaseControllerProvider.requestStart(controllerProvider);
6869

70+
final HttpServletResponse res = (HttpServletResponse)response;
71+
res.addHeader("X-Content-Type-Options", "nosniff" );
72+
res.addHeader("Referrer-Policy", "same-origin" );
73+
6974
try {
7075
sessionFilterBean.doFilter(chain, request, response);
7176
} finally {

0 commit comments

Comments
 (0)