Header always set X-Xss-Protection "1; mode=block" Result; 2.4.37: X-Xss-Protection: 1; mode=block 2.4.38: x-xss-protection: 1; mode=block
If I'm reading the RFC correctly, sensitivity doesn't matter when parsing the header but the 2.4 docs show it outputting as configured as 2.4 has been prior to .38.
Cheers G
