Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

X-Frame-Options #1007

Open
kravietz opened this issue Jan 21, 2019 · 0 comments
Open

X-Frame-Options #1007

kravietz opened this issue Jan 21, 2019 · 0 comments

Comments

@kravietz
Copy link

X-Frame-Options: allowall HTTP header has been enabled on the GDS pages since 2015 by this commit which at best looks unprofessional and at worst opens additional possibilities for fraud by allowing GDS pages to be embedded in frames.

Per my comment under that commit, if there's still need to allow frames for some origins as part of the transition, a much safer allow-from option exists for that purpose.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant