Fixed
Details
Assignee
Guus der KinderenGuus der KinderenReporter
Dan CaseleyDan CaseleyFix versions
Priority
Major
Details
Details
Assignee
Guus der Kinderen
Guus der KinderenReporter
Dan Caseley
Dan CaseleyFix versions
Priority
Created November 25, 2020 at 2:54 PM
Updated January 18, 2021 at 2:34 AM
Resolved January 18, 2021 at 2:34 AM
In OF-997, Admin was enhanced with clickjacking protection with X-Frame-Options header directive. This initially returned a value of "deny" but was updated to return "same".
This generates a console error in Chrome - the correct value is "sameorigin". Without this fix, Admin remains potentially vulnerable to clickjacking.