function readOnly(count){ }
Starting November 20, the site will be set to read-only. On December 4, 2023,
forum discussions will move to the Trailblazer Community.
+ Start a Discussion
Parth thakkar 9Parth thakkar 9 

1.) Browser XSS Protection is not enabled 2.) X-Content-Type-Options header missing

[enter image description here]

Hi Friends ,

anyone heard about OWASP Zap Report ?? Scan request and response. i want create repohttps://eti-massemail.na24.visual.force.com/apex/MassEmail rt for one app of Salesforce. i face an issue in that.

1.) Browser XSS Protection is not enabled 2.) X-Content-Type-Options header missing

how can i resolve please help me if anyone know ??

Ben RoedellBen Roedell
I haven't used OWASP Zap Report yet but the issues that you're describing are likely solved by adding the appropriate URLs to Setup->Security Controls->CORS and/or Setup->Security Controls->Remote Site Settings.

Usually I wouldn't chime in with such a vague response but I figured that after two months of no replies something is better than nothing.
Gabriel NituGabriel Nitu
Please see Platform Security FAQS

https://developer.salesforce.com/page/Platform_Security_FAQS