Skip to content

Fix #18749 - Remove the X-XSS-Protection header - #20427

Open
pongoe wants to merge 1 commit into
phpmyadmin:masterfrom
pongoe:remove-x-xss-protection-18749
Open

pongoe wants to merge 1 commit into
phpmyadmin:masterfrom
pongoe:remove-x-xss-protection-18749

Conversation

@pongoe

@pongoe pongoe commented Aug 17, 2026

Copy link
Copy Markdown

Fixes #18749

I noticed this had been sitting open since 2023 and it looked like a quick one, so I've done it.

The XSS auditor this header controlled is gone from all the major browsers, and OWASP now
says not to send it at all:
https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Headers_Cheat_Sheet.html#x-xss-protection

What I changed:

  • removed the header from src/Header.php
  • removed the matching line from tests/unit/HeaderTest.php
  • added a line to CHANGELOG-6.0.md under Removed

HeaderTest passes and phpcs is clean on both files. This is against master.

Cheers

Browsers dropped the XSS auditor this header controlled, and OWASP now says
not to send it. Removed it from Header::getHttpHeaders() and updated the
unit test.

Fixes phpmyadmin#18749

Signed-off-by: Pongoe <pongoe@users.noreply.github.com>

@williamdes williamdes left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you !

@williamdes williamdes added this to the 6.0.0 milestone Aug 17, 2026
@williamdes williamdes changed the title Remove the X-XSS-Protection header (#18749) Fix #18749 - Remove the X-XSS-Protection header Aug 17, 2026
@codecov

codecov Bot commented Aug 17, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 63.76%. Comparing base (7ff5dd5) to head (1bd58ec).
⚠️ Report is 7 commits behind head on master.

Additional details and impacted files
@@             Coverage Diff              @@
##             master   #20427      +/-   ##
============================================
- Coverage     63.79%   63.76%   -0.04%     
  Complexity    16122    16122              
============================================
  Files           676      676              
  Lines         58014    58009       -5     
============================================
- Hits          37012    36990      -22     
- Misses        21002    21019      +17     
Flag Coverage Δ
dbase-extension 63.68% <ø> (-0.05%) ⬇️
unit-8.2-ubuntu-latest 63.72% <ø> (+<0.01%) ⬆️
unit-8.3-ubuntu-latest 63.72% <ø> (+<0.01%) ⬆️
unit-8.4-ubuntu-latest 63.70% <ø> (-0.03%) ⬇️
unit-8.5-ubuntu-latest 63.73% <ø> (+0.02%) ⬆️
unit-8.6-ubuntu-latest ?

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Reconsider use of X-XSS-Protection

4 participants