webconfig question

Posted on 2014-10-22
Medium Priority
Last Modified: 2014-11-09

What is the role of <clear/> in below code snipped and will it have any effect on functionality of <add name="X-XSS-Protection" value="1"/>

        <add name="X-Frame-Options" value="DENY"/>
        <add name="X-XSS-Protection" value="1"/>

Open in new window

Question by:Dinesh Kumar
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
LVL 28

Expert Comment

by:Dan McFadden
ID: 40396579
It removes all previously declared options.

Reference link:  http://msdn.microsoft.com/en-us/library/aa903345(v=vs.71).aspx


Author Comment

by:Dinesh Kumar
ID: 40396613
1. in my case, I see that I  am having <customHeaders> only once, do <clear/>
 solve any purpose or can I safely remove it?

2. If I remove it I want to ensure that, the following should not affect in any way:

 <add name="X-XSS-Protection" value="1"/>
LVL 28

Expert Comment

by:Dan McFadden
ID: 40396627
In your example config, clear would remove any previously declared (and inherited) keys from your application.  Only the defined keys after the clear will be used.

If you remove it, any upstream (parent) configuration will be included in your app.  But declaring this in your web.config should override anything that inherited.

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

LVL 28

Expert Comment

by:Dan McFadden
ID: 40396632
You can also read thru the article.  Maybe it will make it clearer for you:



Author Comment

by:Dinesh Kumar
ID: 40396697
in my case, it will override  <customHeaders>
defined in machine config?

as I see there is one tag only in  web.config <customHeaders>
LVL 28

Accepted Solution

Dan McFadden earned 2000 total points
ID: 40396723
A clear will remove the customHeaders config section from the web app that uses the configuration above in its web.config.

Then only your X-Frame-Options and X-XSS-Protection items will be used.

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It was really hard time for me to get the understanding of Delegates in C#. I went through many websites and articles but I found them very clumsy. After going through those sites, I noted down the points in a easy way so here I am sharing that unde…
Performance in games development is paramount: every microsecond counts to be able to do everything in less than 33ms (aiming at 16ms). C# foreach statement is one of the worst performance killers, and here I explain why.
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …
Do you want to know how to make a graph with Microsoft Access? First, create a query with the data for the chart. Then make a blank form and add a chart control. This video also shows how to change what data is displayed on the graph as well as form…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question