Skip to content

Instantly share code, notes, and snippets.

@tatsuhiro-t
Last active February 18, 2016 15:43
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save tatsuhiro-t/79ec9a643a24aa9a8868 to your computer and use it in GitHub Desktop.
Save tatsuhiro-t/79ec9a643a24aa9a8868 to your computer and use it in GitHub Desktop.
header fields compiled from https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers, https://en.wikipedia.org/wiki/List_of_HTTP_header_fields, and https://www.owasp.org/index.php/List_of_useful_HTTP_headers + keep-alive and proxy-connection, excluding header field listed in RFC 7541 static table
accept-ch
accept-datetime
accept-features
accept-patch
access-control-allow-credentials
access-control-allow-headers
access-control-allow-methods
access-control-expose-headers
access-control-max-age
access-control-request-headers
access-control-request-method
alternates
connection
content-md5
content-security-policy
content-security-policy-report-only
dnt
forwarded
front-end-https
keep-alive
last-event-id
negotiate
origin
pragma
proxy-connection
public-key-pins
sec-websocket-extensions
sec-websocket-key
sec-websocket-origin
sec-websocket-protocol
sec-websocket-version
set-cookie2
status
tcn
te
trailer
tsv
upgrade
upgrade-insecure-requests
variant-vary
warning
x-att-deviceid
x-content-duration
x-content-security-policy
x-content-type-options
x-dnsprefetch-control
x-forwarded-for
x-forwarded-host
x-frame-options
x-powered-by
x-requested-with
x-ua-compatible
x-wap-profile
x-webkit-csp
x-xss-protection
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment