[
https://issues.apache.org/jira/browse/OFBIZ-9891?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Michael Brohl closed OFBIZ-9891.
--------------------------------
Resolution: Fixed
Fix Version/s: Upcoming Release
This fix/improvement is in trunk r1813276.
> X-Frame-Options configuration is not working
> --------------------------------------------
>
> Key: OFBIZ-9891
> URL:
https://issues.apache.org/jira/browse/OFBIZ-9891> Project: OFBiz
> Issue Type: Bug
> Components: framework
> Affects Versions: Trunk
> Reporter: Michael Brohl
> Assignee: Michael Brohl
> Fix For: Upcoming Release
>
> Attachments: OFBIZ-9891_Bug_x-frame-option.patch
>
>
> The configuration attribute in the controller/site-conf.xsd is "x-frame-option" while the Controller reads "x-frame-options".
> I will change this to be "x-frame-options" in controller/site-conf.xsd also because the Header value is "X-Frame-Options".
> I also propose to introduce another configuration token "none" to be able to switch off this header value for the view, same mechanism as for strict-transport-security.
> What do you think?
--
This message was sent by Atlassian JIRA
(v6.4.14#64029)