Jump in the discussion.

No email address required.

Haha the ExpressJS team doesn't like self promotion? They get really annoyed whenever someone suggests removing the stupid “X-Powered-By: Express” header they inject into every HTTP response. Why is :marseywebshit: self-promotion good but :marseychudindian: self-promotion bad, hmm? :marseyhmm:

Just think of it this way: we give you Express.js for free and in return "trick" you into giving us credit for our hard work or you have to put 1 line of code in your application, which is already code and your developers should understand how to code when using Express.js. :soycry:

To be fair, the X-Powered-By header isn't a huge security issue on its own, it would only help against unusually stupid skiddies who first scan for that specific header and only then start sending requests to a server because they think they have a specific exploit. It's technically sending unnecessary bytes over a network though

Jump in the discussion.

No email address required.

I hate all x headers. So much web scraping failed because some gay proxies decided to set the x-forwarded-for header.

On the other hand I bypassed so much rate limiting by setting the x-forwarded-for header to a random iP and pretending to be a proxy

Jump in the discussion.

No email address required.

It's technically sending unnecessary bytes over a network though

Isn't that all the modern web in general? Bloatware everywhere (except maybe frontend masters)

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.