Uploaded image for project: 'Apache Knox'
  1. Apache Knox
  2. KNOX-700

Add Clickjacking Protection to WebAppSec Provider

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 0.9.0
    • Server
    • None

    Description

      By adding the X-Frame-Options=DENY header to responses, proxied and hosted applications can control whether they can be embedded within another application through Frame, IFrame or Object HTML elements.

      Leveraging this to set them all to DENY adds protection against clickjacking for all proxied and hosted applications within the configured topology.

      Attachments

        1. KNOX-700-002.patch
          18 kB
          Larry McCay
        2. KNOX-700-001.patch
          16 kB
          Larry McCay

        Activity

          People

            lmccay Larry McCay
            lmccay Larry McCay
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: