• Hello Mohit,

    I just installed the new version and was pleased to find that I could now open the headers to add custom settings, which had not been possible previously. This is a big improvement.

    I follow the settings recommended in the Mozilla Observatory mdn docs page. I tried to use unsafe-none for the Cross-Origin-Opener_Policy and the Cross_Origin-Embedder-Policy, but it was not accepted.

    I would also like to ask if it would be possible to add headers for X-Powered-By and unset-Server?

Viewing 3 replies - 1 through 3 (of 3 total)
  • Thread Starter Malae

    (@malae)

    Sorry for the duplicate posting. I had opened another tab to check some information and the Support page had gone when I returned to finish editing it, so I did NOT summit it and had to write the posting again. Surprised to find the duplicate today.
    I also found I cannot add master-only to the X-Permitted-Cross-Domain-Policies and it would not save a custom entry for the Permissions-Policy.
    Should I be able to temporarily disable the plugin without uninstalling by clicking the Disable All Headers button. At present it does not seem to work.

    Plugin Author MOHIT GOYAL

    (@mohitgoyal1108)

    Thanks again for your message — no worries at all about the duplicate post!

    Regarding your questions:

    • We’ll check the issue with adding master-only to X-Permitted-Cross-Domain-Policies and saving custom Permissions-Policy values.
    • The “Disable All Headers” button should temporarily disable all headers without uninstalling — if it’s not working as expected, we’ll fix that in the next update.

    Appreciate your detailed feedback, it’s really helpful!

    Best,
    Mohit

    Thread Starter Malae

    (@malae)

    Hello Mohit,

    Thanks for your reply. I installed on a site today and runng the MDN HTTP Observatory had the following messages: Strict-Transport-Security header not implemented and Content-Type-Options header not implemented
    Both had been set with custom entries. I tried again with default entries and then with Default Reset, but all returned the ‘not implemented’ message.

    • This reply was modified 10 months ago by Malae.
Viewing 3 replies - 1 through 3 (of 3 total)

The topic ‘Custom Settings’ is closed to new replies.