Uploaded image for project: 'Openfire'
  1. Openfire
  2. OF-2005

Default value for adminConsole.frame-options is invalid

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Open
    • Priority: Minor
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: Admin Console
    • Labels:
      None

      Description

      OF-997 introduces a new property that allows the X-Frame-Options to be set:

      response.addHeader("X-Frame-Options", JiveGlobals.getProperty("adminConsole.frame-options", "same"));

      'same' is not a valid value for this header.

      Valid values are:

      • DENY - The page cannot be displayed in a frame, regardless of the site attempting to do so.
      • SAMEORIGIN - The page can only be displayed in a frame on the same origin as the page itself. The spec leaves it up to browser vendors to decide whether this option applies to the top level, the parent, or the whole chain, although it is argued that the option is not very useful unless all ancestors are also in the same origin (see bug 725490). Also see Browser compatibility for support details.

      It's conceivable that instead of 'same', 'SAMEORIGIN' was intended.

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              guus Guus der Kinderen
              Reporter:
              guus Guus der Kinderen
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Dates

                Created:
                Updated: