Skip to content

Conversation

@leerob
Copy link
Contributor

No description provided.

@leerobleerob requested review from a team as code ownersNovember 10, 2023 13:47
@leerobleerob requested review from StephDietz and manovotny and removed request for a teamNovember 10, 2023 13:47
@ijjkijjk added examples Issue was opened via the examples template. created-by: Next.js Docs team PRs by the Docs team. labels Nov 10, 2023
@kodiakhqkodiakhqbot merged commit e507828 into canaryNov 10, 2023
@kodiakhqkodiakhqbot deleted the example-csp branch November 10, 2023 13:55
timneutkens pushed a commit that referenced this pull request Nov 10, 2023
<!-- Thanks for opening a PR! Your contribution is much appreciated. To make sure your PR is handled as smoothly as possible we request that you follow the checklist sections below. Choose the right checklist for the change(s) that you're making: ## For Contributors ### Improving Documentation - Run `pnpm prettier-fix` to fix formatting issues before opening the PR. - Read the Docs Contribution Guide to ensure your contribution follows the docs guidelines: https://nextjs.org/docs/community/contribution-guide ### Adding or Updating Examples - The "examples guidelines" are followed from our contributing doc https://github.com/vercel/next.js/blob/canary/contributing/examples/adding-examples.md - Make sure the linting passes by running `pnpm build && pnpm lint`. See https://github.com/vercel/next.js/blob/canary/contributing/repository/linting.md ### Fixing a bug - Related issues linked using `fixes #number` - Tests added. See: https://github.com/vercel/next.js/blob/canary/contributing/core/testing.md#writing-tests-for-nextjs - Errors have a helpful link attached, see https://github.com/vercel/next.js/blob/canary/contributing.md ### Adding a feature - Implements an existing feature request or RFC. Make sure the feature request has been accepted for implementation before opening a PR. (A discussion must be opened, see https://github.com/vercel/next.js/discussions/new?category=ideas) - Related issues/discussions are linked using `fixes #number` - e2e tests added (https://github.com/vercel/next.js/blob/canary/contributing/core/testing.md#writing-tests-for-nextjs) - Documentation added - Telemetry added. In case of a feature if it's used or not. - Errors have a helpful link attached, see https://github.com/vercel/next.js/blob/canary/contributing.md ## For Maintainers - Minimal description (aim for explaining to someone not on the team to understand the PR) - When linking to a Slack thread, you might want to share details of the conclusion - Link both the Linear (Fixes NEXT-xxx) and the GitHub issues - Add review comments if necessary to explain to the reviewer the logic behind a change ### What? ### Why? ### How? Closes NEXT- Fixes # --> ### What? Avoid copying request headers to response ### Why? Copying request headers to response allows for reflection attacks #57410 ### How? Remove the `headers:` property assignment cc @leerob Followup to #58300Fixes#57410
delbaoliveira added a commit that referenced this pull request Nov 15, 2023
@github-actionsgithub-actionsbot locked as resolved and limited conversation to collaborators Nov 25, 2023
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

created-by: Next.js Docs teamPRs by the Docs team.examplesIssue was opened via the examples template.locked

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@leerob@timneutkens@ijjk