11// Copyright (c) .NET Foundation. All rights reserved.
22// Licensed under the Apache License, Version 2.0. See License.txt in the project root for license information.
33
4+ using System ;
45using System . Collections . Generic ;
56using Microsoft . VisualStudio . TestTools . WebTesting ;
67using NuGetGallery . FunctionalTests . Helpers ;
@@ -23,7 +24,7 @@ public override IEnumerator<WebTestRequest> GetRequestEnumerator()
2324 // Send a request to home page and check for security headers.
2425 var homePageRequest = new WebTestRequest ( UrlHelper . BaseUrl ) ;
2526 homePageRequest . ParseDependentRequests = false ;
26- homePageRequest . ValidateResponse += new ValidationRuleFindHeaderText ( "X-Frame-Options: deny" ) . Validate ;
27+ homePageRequest . ValidateResponse += new ValidationRuleFindHeaderText ( "X-Frame-Options: DENY" , StringComparison . OrdinalIgnoreCase ) . Validate ;
2728 homePageRequest . ValidateResponse += new ValidationRuleFindHeaderText ( "X-XSS-Protection: 1; mode=block" ) . Validate ;
2829 homePageRequest . ValidateResponse += new ValidationRuleFindHeaderText ( "X-Content-Type-Options: nosniff" ) . Validate ;
2930 homePageRequest . ValidateResponse += new ValidationRuleFindHeaderText ( "Strict-Transport-Security: max-age=31536000" ) . Validate ;
@@ -32,7 +33,7 @@ public override IEnumerator<WebTestRequest> GetRequestEnumerator()
3233 // Send a request to Packages page and check for security headers.
3334 var packagesPageRequest = new WebTestRequest ( UrlHelper . PackagesPageUrl ) ;
3435 packagesPageRequest . ParseDependentRequests = false ;
35- packagesPageRequest . ValidateResponse += new ValidationRuleFindHeaderText ( "X-Frame-Options: deny" ) . Validate ;
36+ packagesPageRequest . ValidateResponse += new ValidationRuleFindHeaderText ( "X-Frame-Options: DENY" , StringComparison . OrdinalIgnoreCase ) . Validate ;
3637 packagesPageRequest . ValidateResponse += new ValidationRuleFindHeaderText ( "X-XSS-Protection: 1; mode=block" ) . Validate ;
3738 packagesPageRequest . ValidateResponse += new ValidationRuleFindHeaderText ( "X-Content-Type-Options: nosniff" ) . Validate ;
3839 packagesPageRequest . ValidateResponse += new ValidationRuleFindHeaderText ( "Strict-Transport-Security: max-age=31536000" ) . Validate ;
0 commit comments