Dotclear

Changeset 3619:1b4fdf28e548


Ignore:
Timestamp:
12/12/17 14:00:19 (8 years ago)
Author:
franck <carnet.franck.paul@…>
Branch:
default
Message:

Add Referrer-Policy header in admin pages (thanks Nicolas Hoffmann →  https://openweb.eu.org/articles/referrer-policy)

File:
1 edited

Legend:

Unmodified
Added
Removed
  • inc/admin/lib.dc.page.php

    r3566 r3619  
    9494          # Content-Type 
    9595          $headers['content-type'] = 'Content-Type: text/html; charset=UTF-8'; 
     96 
     97          # Referrer Policy for admin pages 
     98          $headers['referrer'] = 'Referrer-Policy: strict-origin'; 
    9699 
    97100          # Prevents Clickjacking as far as possible 
     
    421424          header('Content-Type: text/html; charset=UTF-8'); 
    422425 
    423           // Prevents Clickjacking as far as possible 
     426          # Referrer Policy for admin pages 
     427          header('Referrer-Policy: strict-origin'); 
     428 
     429          # Prevents Clickjacking as far as possible 
    424430          header('X-Frame-Options: SAMEORIGIN'); // FF 3.6.9+ Chrome 4.1+ IE 8+ Safari 4+ Opera 10.5+ 
    425431 
Note: See TracChangeset for help on using the changeset viewer.

Sites map