Skip to content

Releases: nelmio/NelmioSecurityBundle

1.6.0

01 Feb 11:00
Compare
Choose a tag to compare
  • Added a forced_ssl.hsts_preload flag to allow adding the preload attribute on HSTS headers

1.5.0

01 Jan 20:49
Compare
Choose a tag to compare
  • Added ability to have different configs for both reported and enforced CSP rules
  • Added support for ALLOW and ALLOW FROM syntaxes in the Clickjacking Protection
  • Added support for HHvM and PHP 5.6
  • Fixed enabling of cookie signing when the cookie list is empty

1.4.0

18 Feb 10:55
Compare
Choose a tag to compare
  • Added default controller to log CSP violations
  • Added a flag to remove outdated non-standard CSP headers and only send the Content-Security-Policy one

1.3.0

07 Jan 23:15
Compare
Choose a tag to compare
  • Added support for setting the X-Content-Type-Options header

1.2.0

29 Jul 15:39
Compare
Choose a tag to compare
  • Added Content-Security-Policy (CSP) 1.0 support
  • Added forced_ssl.whitelist property to define URLs that do not need to be force-redirected
  • Fixed session loss bug on 404 URLs in the CookieSessionHandler