Prevent Clickjacking by adding additional headers:

header('X-Frame-Options: Sameorigin');
                header('X-XSS-Protection: 1; mode=block');
                header('X-Content-Type-Options: nosniff');

Thanks to Lukas Reschke for reporting this issue (and many more).
This commit is contained in:
Thomas Mueller 2012-05-14 15:34:28 +02:00
parent 0c8740c1d5
commit bda2dbec1f

View file

@ -156,7 +156,10 @@ class OC_Template{
$this->application = $app;
$this->vars = array();
$this->l10n = OC_L10N::get($app);
header('X-Frame-Options: Sameorigin');
header('X-XSS-Protection: 1; mode=block');
header('X-Content-Type-Options: nosniff');
$this->findTemplate($name);
}