summaryrefslogtreecommitdiffstats
path: root/jdisc-security-filters
diff options
context:
space:
mode:
authorMorten Tokle <mortent@yahooinc.com>2022-06-28 15:11:12 +0200
committerMorten Tokle <mortent@yahooinc.com>2022-06-28 15:11:12 +0200
commit86e3f430296bba80fd49ef179b83912b07a47d49 (patch)
tree943332ab982f6a5059a41b204a61a766f123330b /jdisc-security-filters
parentea382e408d7c60c8395add87a9065db7f49ac03a (diff)
Add x-frame-options
Diffstat (limited to 'jdisc-security-filters')
-rw-r--r--jdisc-security-filters/src/main/java/com/yahoo/jdisc/http/filter/security/misc/SecurityHeadersResponseFilter.java1
1 files changed, 1 insertions, 0 deletions
diff --git a/jdisc-security-filters/src/main/java/com/yahoo/jdisc/http/filter/security/misc/SecurityHeadersResponseFilter.java b/jdisc-security-filters/src/main/java/com/yahoo/jdisc/http/filter/security/misc/SecurityHeadersResponseFilter.java
index 21edd1c8e10..24cd9245b61 100644
--- a/jdisc-security-filters/src/main/java/com/yahoo/jdisc/http/filter/security/misc/SecurityHeadersResponseFilter.java
+++ b/jdisc-security-filters/src/main/java/com/yahoo/jdisc/http/filter/security/misc/SecurityHeadersResponseFilter.java
@@ -18,5 +18,6 @@ public class SecurityHeadersResponseFilter implements SecurityResponseFilter {
response.setHeader("Pragma", "no-cache");
response.setHeader("Strict-Transport-Security", "max-age=31536000; includeSubDomains");
response.setHeader("X-Content-Type-Options", "nosniff");
+ response.setHeader("X-Frame-Options", "DENY");
}
}