Homestyx hydra
Diffusion hydra 5284053c0e30

Add X-Frame-Options for all response

Description

Add X-Frame-Options for all response

Summary:
we use to only add X-Frame-Options for AphrontWebpageResponse.
There some security concern about it. Example of a drag-drop attack:
http://sites.google.com/site/tentacoloviola/. The fix is to add it to
all AphrontResponse.

Test Plan:
View page which disalble this option still works (like the
xhpast tree page); verify that the AphrontAjaxResponse contains the
X-Frame-Options in the header.

Reviewers: epriestley, benmathews

Reviewed By: epriestley

CC: nh, aran, jungejason, epriestley

Differential Revision: 926

Details

Provenance
Jason GeAuthored on Sep 13 2011, 7:38 PM
sirocylPushed on Oct 16 2024, 5:49 AM
Parents
R1:2f218ac745d5: Provide more thorough defaults in the configuration guide template
Branches
Unknown
Tags
Unknown

Event Timeline