Solved

webconfig question

Posted on 2014-10-22
6
114 Views
Last Modified: 2014-11-09
Hi

What is the role of <clear/> in below code snipped and will it have any effect on functionality of <add name="X-XSS-Protection" value="1"/>


<httpProtocol>
      <customHeaders>
        <clear/>
        <add name="X-Frame-Options" value="DENY"/>
        <add name="X-XSS-Protection" value="1"/>
      </customHeaders>
    </httpProtocol>

Open in new window



Thanks
meetDinesh
0
Comment
Question by:Dinesh Kumar
  • 4
  • 2
6 Comments
 
LVL 26

Expert Comment

by:Dan McFadden
Comment Utility
It removes all previously declared options.

Reference link:  http://msdn.microsoft.com/en-us/library/aa903345(v=vs.71).aspx

Dan
0
 

Author Comment

by:Dinesh Kumar
Comment Utility
1. in my case, I see that I  am having <customHeaders> only once, do <clear/>
 solve any purpose or can I safely remove it?

2. If I remove it I want to ensure that, the following should not affect in any way:

 <add name="X-XSS-Protection" value="1"/>
0
 
LVL 26

Expert Comment

by:Dan McFadden
Comment Utility
In your example config, clear would remove any previously declared (and inherited) keys from your application.  Only the defined keys after the clear will be used.

If you remove it, any upstream (parent) configuration will be included in your app.  But declaring this in your web.config should override anything that inherited.

Dan
0
What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 
LVL 26

Expert Comment

by:Dan McFadden
Comment Utility
You can also read thru the article.  Maybe it will make it clearer for you:

http://stackoverflow.com/questions/7626440/web-config-clear

Dan
0
 

Author Comment

by:Dinesh Kumar
Comment Utility
in my case, it will override  <customHeaders>
defined in machine config?

as I see there is one tag only in  web.config <customHeaders>
0
 
LVL 26

Accepted Solution

by:
Dan McFadden earned 500 total points
Comment Utility
A clear will remove the customHeaders config section from the web app that uses the configuration above in its web.config.

Then only your X-Frame-Options and X-XSS-Protection items will be used.
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Suggested Solutions

User art_snob (http://www.experts-exchange.com/M_6114203.html) encountered strange behavior of Android Web browser on his Mobile Web site. It took a while to find the true cause. It happens so, that the Android Web browser (at least up to OS ver. 2.…
Exception Handling is in the core of any application that is able to dignify its name. In this article, I'll guide you through the process of writing a DRY (Don't Repeat Yourself) Exception Handling mechanism, using Aspect Oriented Programming.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now