Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fixed #30426 -- Changed X_FRAME_OPTIONS setting default to DENY. #11751

Merged
merged 1 commit into from Sep 9, 2019

Conversation

claudep
Copy link
Member

@claudep claudep commented Sep 7, 2019

No description provided.

docs/releases/3.0.txt Outdated Show resolved Hide resolved
docs/ref/clickjacking.txt Outdated Show resolved Hide resolved
Copy link
Member

@felixxm felixxm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@claudep Thanks for this patch 👍 , we should adjust message for security.W019: "... The default is ``'SAMEORIGIN'``,...

@felixxm felixxm changed the title Fixed #30426 -- Made X_FRAME_OPTIONS default to DENY. Fixed #30426 -- Changed X_FRAME_OPTIONS setting default to DENY. Sep 7, 2019
@felixxm felixxm self-assigned this Sep 9, 2019
@felixxm
Copy link
Member

felixxm commented Sep 9, 2019

@claudep Thanks! I pushed minor edits and changed a check message in docs/ref/checks.txt.

@felixxm felixxm merged commit 05d0eca into django:master Sep 9, 2019
@claudep
Copy link
Member Author

claudep commented Sep 9, 2019

Thanks Mariusz!
Hopefully we can still push the Referrer-Policy part of PR #11735 in 3.0 before the feature freeze!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
3 participants