You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Aug 6, 2021. It is now read-only.
[TASK] Document Clickjacking attack scenario and defense
This patch adds two sections to the Security Guide which explain the
Clickjacking attack scenario and the defense against it in the FE by
sending X-Frame-Options in the HTTP header.
We also mention that this header is sent in the backend by default.
One section in chapter "Guidelines for system administrators" (web
server configuration example) and another section in chapter "Guidelines
for integrators".
Resolves: #57144
Related: #54201
Reviewed-by: Helmut Hummel
0 commit comments