Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium


webconfig question

Posted on 2014-10-22
Medium Priority
Last Modified: 2014-11-09

What is the role of <clear/> in below code snipped and will it have any effect on functionality of <add name="X-XSS-Protection" value="1"/>

        <add name="X-Frame-Options" value="DENY"/>
        <add name="X-XSS-Protection" value="1"/>

Open in new window

Question by:Dinesh Kumar
  • 4
  • 2
LVL 29

Expert Comment

by:Dan McFadden
ID: 40396579
It removes all previously declared options.

Reference link:  http://msdn.microsoft.com/en-us/library/aa903345(v=vs.71).aspx


Author Comment

by:Dinesh Kumar
ID: 40396613
1. in my case, I see that I  am having <customHeaders> only once, do <clear/>
 solve any purpose or can I safely remove it?

2. If I remove it I want to ensure that, the following should not affect in any way:

 <add name="X-XSS-Protection" value="1"/>
LVL 29

Expert Comment

by:Dan McFadden
ID: 40396627
In your example config, clear would remove any previously declared (and inherited) keys from your application.  Only the defined keys after the clear will be used.

If you remove it, any upstream (parent) configuration will be included in your app.  But declaring this in your web.config should override anything that inherited.

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

LVL 29

Expert Comment

by:Dan McFadden
ID: 40396632
You can also read thru the article.  Maybe it will make it clearer for you:



Author Comment

by:Dinesh Kumar
ID: 40396697
in my case, it will override  <customHeaders>
defined in machine config?

as I see there is one tag only in  web.config <customHeaders>
LVL 29

Accepted Solution

Dan McFadden earned 2000 total points
ID: 40396723
A clear will remove the customHeaders config section from the web app that uses the configuration above in its web.config.

Then only your X-Frame-Options and X-XSS-Protection items will be used.

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Calculating holidays and working days is a function that is often needed yet it is not one found within the Framework. This article presents one approach to building a working-day calculator for use in .NET.
This article aims to explain the working of CircularLogArchiver. This tool was designed to solve the buildup of log file in cases where systems do not support circular logging or where circular logging is not enabled
Loops Section Overview
Is your OST file inaccessible, Need to transfer OST file from one computer to another? Want to convert OST file to PST? If the answer to any of the above question is yes, then look no further. With the help of Stellar OST to PST Converter, you can e…
Suggested Courses
Course of the Month15 days, 9 hours left to enroll

580 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question