Advertisement

security headers : X-Content-Type-Options and others

Discussion regarding Joomla! 5.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Post Reply
_obfuscated_
Joomla! Fledgling
Joomla! Fledgling
Posts: 1
Joined: Mon Feb 17, 2025 4:54 pm

security headers : X-Content-Type-Options and others

Post by _obfuscated_ » Mon Feb 17, 2025 5:30 pm

Hello!

I already use the “System - HTTP Headers” plugin to configure headers.
Since I'm new to it, I have a few questions about it:
- why use 64 bytes for the nonce? Isn't 16 enough?
- Is it possible to configure X-Content-Type-Options (same question for CORP)? I don't find it.
- more generally, is it possible to add custom headers ourself? (meaning: have a "custom" possibility in the http header list which give a blank box)

Thank you,

Advertisement
Advertisement
Post Reply

Return to “Security in Joomla! 5.x”