We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent fb66f60 commit e8059e8Copy full SHA for e8059e8
Bugzilla/App.pm
@@ -181,6 +181,12 @@ sub startup {
181
$res->headers->header('Referrer-policy' => 'same-origin');
182
}
183
184
+ # Add Cross-Origin-Opener-Policy header if not already set
185
+ # This header controls the relationship between browsing contexts
186
+ # to prevent cross-origin attacks like Spectre.
187
+ $res->headers->header(
188
+ 'Cross-Origin-Opener-Policy' => 'same-origin-allow-popups');
189
+
190
unless ($res->headers->content_security_policy) {
191
if (my $csp = $c->content_security_policy) {
192
$res->headers->header($csp->header_name, $csp->value);
0 commit comments