Browse Source

Merged #166 "Fix XRF vulnerability"

tags/v1.6.1
James Moger 9 years ago
parent
commit
30dc4e420a
1 changed files with 3 additions and 0 deletions
  1. 3
    0
      src/main/java/com/gitblit/wicket/pages/BasePage.java

+ 3
- 0
src/main/java/com/gitblit/wicket/pages/BasePage.java View File

@@ -166,6 +166,9 @@ public abstract class BasePage extends SessionPage {
// use default Wicket caching behavior
super.setHeaders(response);
}
// XRF vulnerability. issue-500 / ticket-166
response.setHeader("X-Frame-Options", "SAMEORIGIN");
}
/**

Loading…
Cancel
Save