Browse Source
			
			
			Changed frame-ancestors to use 'self'
			
			
				pull/293/head
			
			
		 
		
			
				
					
						 dheimerl
					
					7 years ago
						dheimerl
					
					7 years ago
					
						
							committed by
							
								 GitHub
								GitHub
							
						 
					
				 
				
			 
		 
		
			
				
					
					No known key found for this signature in database
					
						
							GPG Key ID: 4AEE18F83AFDEB23
						
					
				
			
		
		
		
	
		
			
				 1 changed files with 
1 additions and 
1 deletions
			 
			
		 
		
			
				- 
					
					
					 
					src/api/web.rs
				
				
				
					
						
							
								
									
	
		
			
				
					|  |  | @ -56,7 +56,7 @@ impl<'r, R: Responder<'r>> Responder<'r> for WebHeaders<R> { | 
			
		
	
		
			
				
					|  |  |  |                 res.set_raw_header("X-Frame-Options", "SAMEORIGIN"); | 
			
		
	
		
			
				
					|  |  |  |                 res.set_raw_header("X-Content-Type-Options", "nosniff"); | 
			
		
	
		
			
				
					|  |  |  |                 res.set_raw_header("X-XSS-Protection", "1; mode=block"); | 
			
		
	
		
			
				
					|  |  |  |                 let csp = "frame-ancestors chrome-extension://nngceckbapebfimnlniiiahkandclblb moz-extension://* ".to_owned() + &CONFIG.domain + ";"; | 
			
		
	
		
			
				
					|  |  |  |                 let csp = "frame-ancestors 'self' chrome-extension://nngceckbapebfimnlniiiahkandclblb moz-extension://*;"; | 
			
		
	
		
			
				
					|  |  |  |                 res.set_raw_header("Content-Security-Policy", csp); | 
			
		
	
		
			
				
					|  |  |  | 
 | 
			
		
	
		
			
				
					|  |  |  |                 Ok(res) | 
			
		
	
	
		
			
				
					|  |  | 
 |