Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Only allow iframes to be loaded from our domain #7904

Merged
merged 3 commits into from Feb 18, 2021

Conversation

SantoDE
Copy link
Contributor

@SantoDE SantoDE commented Feb 17, 2021

What does this PR do?

Only allows iframes to be loaded from our domain

Motivation

Be more secure :)

More

  • Added/updated tests
  • Added/updated documentation

Additional Notes

pkg/api/dashboard.go Outdated Show resolved Hide resolved
@ldez ldez added this to To review in v2 via automation Feb 18, 2021
@ldez ldez added this to the 2.4 milestone Feb 18, 2021
@ldez ldez self-requested a review February 18, 2021 11:29
Copy link
Member

@rtribotte rtribotte left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👌

Copy link
Member

@ldez ldez left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@traefiker traefiker merged commit bae28c5 into traefik:v2.4 Feb 18, 2021
2 checks passed
v2 automation moved this from To review to Done Feb 18, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
v2
Done
Development

Successfully merging this pull request may close these issues.

None yet

6 participants