SecurityOptions
Index
Properties
csp
csrf
whether defend csrf attack default enable and use cookie
hsts
whether enable Strict-Transport-Security response header default not enable and maxAge equals one year
noopen
whether enable IE automaticlly download open default not enable
nosniff
whether enable IE8 automaticlly dedect mime default not enable
xframe
whether enable X-Frame-Options response header default enable and value equals SAMEORIGIN
xssProtection
whether enable IE8 XSS Filter, default is open default enable
content security policy config default not enable