Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-21881

Make X-Frame-Options configurable

    XMLWordPrintable

Details

    Description

      Jenkins 1.532.2 sets X-Frame-Options to sameorigin |https://github.com/cloudbees/hudson/commit/16931bd7bf7560e26ef98328b8e95e803d0e90f6]. While this prevents attacks via frame embedding, it also prevents any desirable embedding of Jenkins in a frame.

      This should be configurable "somehow." Either via an extension point, or allowing PageDecorators to set the header property by changing the order of layout.jelly.

      Attachments

        Issue Links

          Activity

            recampbell Ryan Campbell created issue -
            jglick Jesse Glick made changes -
            Field Original Value New Value
            Labels lts-candidate api lts-candidate security
            jglick Jesse Glick made changes -
            Link This issue is duplicated by JENKINS-21842 [ JENKINS-21842 ]
            jglick Jesse Glick made changes -
            Link This issue is blocking SECURITY-80 [ SECURITY-80 ]
            jglick Jesse Glick made changes -
            Status Open [ 1 ] In Progress [ 3 ]
            danielbeck Daniel Beck made changes -
            Link This issue is duplicated by JENKINS-22168 [ JENKINS-22168 ]
            abubadabu Timm Drevensek made changes -
            Link This issue is related to JENKINS-22430 [ JENKINS-22430 ]
            danielbeck Daniel Beck made changes -
            Assignee Daniel Beck [ danielbeck ]
            danielbeck Daniel Beck made changes -
            Remote Link This issue links to "PR 1391 (Web Link)" [ 11502 ]
            scm_issue_link SCM/JIRA link daemon made changes -
            Resolution Fixed [ 1 ]
            Status In Progress [ 3 ] Resolved [ 5 ]
            danielbeck Daniel Beck made changes -
            Labels api lts-candidate security api security
            rtyler R. Tyler Croy made changes -
            Workflow JNJira [ 153882 ] JNJira + In-Review [ 194737 ]

            People

              danielbeck Daniel Beck
              recampbell Ryan Campbell
              Votes:
              7 Vote for this issue
              Watchers:
              14 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: