Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Remove the X-XSS-Protection header
Browsers dropped the XSS auditor this header controlled, and OWASP now says
not to send it. Removed it from Header::getHttpHeaders() and updated the
unit test.

Fixes #18749

Signed-off-by: Pongoe <pongoe@users.noreply.github.com>
  • Loading branch information
pongoe committed Aug 17, 2026
commit 1bd58ece543e7348a294ec517eaa7f1cb1d70d3a
1 change: 1 addition & 0 deletions CHANGELOG-6.0.md
Original file line number Diff line number Diff line change
Expand Up @@ -98,5 +98,6 @@ All notable changes of the phpMyAdmin 6.0 release series are documented in this
* [#19550](https://github.com/phpmyadmin/phpmyadmin/pull/19550): Replace jQuery UI's tooltip with Bootstrap's Tooltip
* [#19852](https://github.com/phpmyadmin/phpmyadmin/pull/19852): Bump Node version to 20
* [#19854](https://github.com/phpmyadmin/phpmyadmin/pull/19854): Drop support for BaconQrCode v2
* [#18749](https://github.com/phpmyadmin/phpmyadmin/issues/18749): Remove the obsolete `X-XSS-Protection` HTTP header

[6.0.0]: https://github.com/phpmyadmin/phpmyadmin/compare/QA_5_2...master
7 changes: 0 additions & 7 deletions src/Header.php
Original file line number Diff line number Diff line change
Expand Up @@ -334,13 +334,6 @@ public function getHttpHeaders(ClockInterface|null $clock = null): array

'Content-Security-Policy' => $this->getCspHeader(),

/**
* Re-enable possible disabled XSS filters.
*
* @see https://developer.mozilla.org/docs/Web/HTTP/Headers/X-XSS-Protection
*/
'X-XSS-Protection' => '1; mode=block',

/**
* "nosniff", prevents Internet Explorer and Google Chrome from MIME-sniffing
* a response away from the declared content-type.
Expand Down
1 change: 0 additions & 1 deletion tests/unit/HeaderTest.php
Original file line number Diff line number Diff line change
Expand Up @@ -268,7 +268,6 @@ public function testGetHttpHeaders(
$expected = [
'Referrer-Policy' => 'same-origin',
'Content-Security-Policy' => $expectedCsp,
'X-XSS-Protection' => '1; mode=block',
'X-Content-Type-Options' => 'nosniff',
'X-Permitted-Cross-Domain-Policies' => 'none',
'X-Robots-Tag' => 'noindex, nofollow',
Expand Down
Loading