Disable framing

Set the X-Frame-Options to DENY for added security.
v1.18.x
Jet 11 years ago
parent 6c3e121b6c
commit 73dafa6aff

@ -112,6 +112,10 @@ var express = require('express'),
app.use(function (req, res, next) {
nconf.set('https', req.secure);
res.locals.csrf_token = req.session._csrf;
// Disable framing
res.setHeader "x-frame-options", "DENY"
next();
});

Loading…
Cancel
Save