Closed Bug 944817 Opened 12 years ago Closed 12 years ago

Add X-Frame-Options header

Categories

(Webmaker Graveyard :: Login, defect)

defect
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: jon, Assigned: jon)

References

()

Details

Attachments

(1 file)

The login server has no frameable content, so we can set the X-Frame-Options: Deny header to prevent clickjacking attacks.
Attachment #8341126 - Flags: review?(cade) → review+
Status: ASSIGNED → RESOLVED
Closed: 12 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: