mirror of
git://git.yoctoproject.org/layerindex-web.git
synced 2025-07-19 20:59:01 +02:00
Enable clickjacking protection in default settings file
Signed-off-by: Paul Eggleton <paul.eggleton@linux.intel.com>
This commit is contained in:
parent
5b9f65880d
commit
dd757d7bfb
|
@ -105,9 +105,13 @@ MIDDLEWARE_CLASSES = (
|
||||||
'django.middleware.csrf.CsrfViewMiddleware',
|
'django.middleware.csrf.CsrfViewMiddleware',
|
||||||
'django.contrib.auth.middleware.AuthenticationMiddleware',
|
'django.contrib.auth.middleware.AuthenticationMiddleware',
|
||||||
'django.contrib.messages.middleware.MessageMiddleware',
|
'django.contrib.messages.middleware.MessageMiddleware',
|
||||||
|
'django.middleware.clickjacking.XFrameOptionsMiddleware',
|
||||||
'reversion.middleware.RevisionMiddleware',
|
'reversion.middleware.RevisionMiddleware',
|
||||||
)
|
)
|
||||||
|
|
||||||
|
# Clickjacking protection
|
||||||
|
X_FRAME_OPTIONS = 'DENY'
|
||||||
|
|
||||||
from django.conf.global_settings import TEMPLATE_CONTEXT_PROCESSORS as TCP
|
from django.conf.global_settings import TEMPLATE_CONTEXT_PROCESSORS as TCP
|
||||||
TEMPLATE_CONTEXT_PROCESSORS = TCP + (
|
TEMPLATE_CONTEXT_PROCESSORS = TCP + (
|
||||||
'django.core.context_processors.request',
|
'django.core.context_processors.request',
|
||||||
|
|
Loading…
Reference in New Issue
Block a user