clickjacking prevention via X-Frame-Options and Content-Security-Policy headers

This commit is contained in:
Oliver Gorwits
2021-10-06 16:44:36 +01:00
parent 726e8c611a
commit 381f412df9
3 changed files with 10 additions and 0 deletions

View File

@@ -533,3 +533,6 @@ template: 'netdisco_template_toolkit'
route_cache: true
appname: 'Netdisco'
behind_proxy: false
HTTP-Header-X-Frame-Options: 'DENY'
HTTP-Header-Content-Security-Policy: 'none'