mirror of
https://github.com/gogs/gogs.git
synced 2025-05-30 03:03:02 +00:00
context: add X-Frame-Options header (#6411)
Co-authored-by: ᴜɴᴋɴᴡᴏɴ <u@gogs.io>
This commit is contained in:
parent
6f735cc2da
commit
997ba0fef0
@ -17,6 +17,8 @@ All notable changes to Gogs are documented in this file.
|
||||
|
||||
### Fixed
|
||||
|
||||
- Add `X-Frame-Options` header to prevent Clickjacking. [#6409](https://github.com/gogs/gogs/issues/6409)
|
||||
|
||||
### Removed
|
||||
|
||||
- ⚠️ Migrations before 0.12 are removed, installations not on 0.12 should upgrade to it to run the migrations and then upgrade to 0.13.
|
||||
|
@ -289,6 +289,7 @@ func Contexter() macaron.Handler {
|
||||
// 🚨 SECURITY: Prevent MIME type sniffing in some browsers,
|
||||
// see https://github.com/gogs/gogs/issues/5397 for details.
|
||||
c.Header().Set("X-Content-Type-Options", "nosniff")
|
||||
c.Header().Set("X-Frame-Options", "DENY")
|
||||
|
||||
ctx.Map(c)
|
||||
}
|
||||
|
Loading…
x
Reference in New Issue
Block a user