Details
-
New Feature
-
Status: Resolved (View Workflow)
-
Minor
-
Resolution: Fixed
Description
Jenkins 1.532.2 sets X-Frame-Options to sameorigin |https://github.com/cloudbees/hudson/commit/16931bd7bf7560e26ef98328b8e95e803d0e90f6]. While this prevents attacks via frame embedding, it also prevents any desirable embedding of Jenkins in a frame.
This should be configurable "somehow." Either via an extension point, or allowing PageDecorators to set the header property by changing the order of layout.jelly.
Attachments
Issue Links
- is duplicated by
-
JENKINS-21842 Need a way to permit Jenkins to be visible in selected iframes
-
- Resolved
-
-
JENKINS-22168 Jenkins does not work inside HTML frame's anymore
-
- Resolved
-
- is related to
-
JENKINS-22430 XFrame Filter Plugin forgets settings upon Jenkins restart
-
- Resolved
-
- links to
Activity
Field | Original Value | New Value |
---|---|---|
Labels | lts-candidate | api lts-candidate security |
Link |
This issue is duplicated by |
Link | This issue is blocking SECURITY-80 [ SECURITY-80 ] |
Status | Open [ 1 ] | In Progress [ 3 ] |
Link |
This issue is duplicated by |
Link |
This issue is related to |
Assignee | Daniel Beck [ danielbeck ] |
Remote Link | This issue links to "PR 1391 (Web Link)" [ 11502 ] |
Resolution | Fixed [ 1 ] | |
Status | In Progress [ 3 ] | Resolved [ 5 ] |
Labels | api lts-candidate security | api security |
Workflow | JNJira [ 153882 ] | JNJira + In-Review [ 194737 ] |