Skip to content

Deprecate HTTP_SEND_X_FRAME_OPTIONS #4474

@TimWolla

Description

@TimWolla

Embedding in frames:

  • Reduces the security (by forcing SameSite=none on cookies and allowing clickjacking).
  • Imposes bad UX (by not showing the actual URL in the URL bar).
  • Interoperates especially badly with Firefox' scoped cookie jars, because WoltLab Suite will see differing cookies depending on whether the site is embedded in a frame or not.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions