Web Security / Building secure apps
Lesson 20 of 27
Security headers
Headers like Strict-Transport-Security, X-Content-Type-Options and X-Frame-Options switch on browser protections with one line each.
Key points
- HSTS forces HTTPS
- nosniff stops content-type guessing
- frame-ancestors stops clickjacking
Quiz · +10 XP
Which header forces browsers to always use HTTPS?
Log in to save progress and earn XP.