Slide 38
Slide 38 text
HTTP Security Headers
(def middleware-settings
{:session {:cookie-attrs {:http-only true :secure true}}
:security {:anti-forgery true
:xss-protection {:enable? true, :mode :block}
:frame-options :sameorigin
:content-type-options :nosniff
:ssl-redirect true
:hsts true}})
"Ring-Defaults", e.g."api-defaults", "site-defaults",
"secure-site-defaults", ...