diff --git a/src/webserver.js b/src/webserver.js index e03e3382df..e23d9263f5 100644 --- a/src/webserver.js +++ b/src/webserver.js @@ -112,6 +112,10 @@ var express = require('express'), app.use(function (req, res, next) { nconf.set('https', req.secure); res.locals.csrf_token = req.session._csrf; + + // Disable framing + res.setHeader "x-frame-options", "DENY" + next(); });