How to set HTTP Headers like X-Frame-Options in EAP 7?
Issue
- X-Frame-Options header is not included in the HTTP response to protect against 'ClickJacking' attacks
- We recently had a penetration test done of your JBoss EAP 7 systems and the issue of XSS protection was raised
- We need to add http response headers to fix QID-11827
Environment
- Red Hat Enterprise Application Platform(EAP)
- 7
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.