Jump in the discussion.

No email address required.

Haha the ExpressJS team doesn't like self promotion? They get really annoyed whenever someone suggests removing the stupid “X-Powered-By: Express” header they inject into every HTTP response. Why is :marseywebshit: self-promotion good but :marseychudindian: self-promotion bad, hmm? :marseyhmm:

Just think of it this way: we give you Express.js for free and in return "trick" you into giving us credit for our hard work or you have to put 1 line of code in your application, which is already code and your developers should understand how to code when using Express.js. :soycry:

To be fair, the X-Powered-By header isn't a huge security issue on its own, it would only help against unusually stupid skiddies who first scan for that specific header and only then start sending requests to a server because they think they have a specific exploit. It's technically sending unnecessary bytes over a network though

Jump in the discussion.

No email address required.

It's technically sending unnecessary bytes over a network though

Isn't that all the modern web in general? Bloatware everywhere (except maybe frontend masters)

Jump in the discussion.

No email address required.

I hate all x headers. So much web scraping failed because some gay proxies decided to set the x-forwarded-for header.

On the other hand I bypassed so much rate limiting by setting the x-forwarded-for header to a random iP and pretending to be a proxy

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.