Forbid iframes
This prevents clickjacking attacks.
This commit is contained in:
7
main.py
7
main.py
@@ -33,6 +33,13 @@ class Role:
|
|||||||
MODERATOR = 1
|
MODERATOR = 1
|
||||||
ADMIN = 2
|
ADMIN = 2
|
||||||
|
|
||||||
|
@app.after_request
|
||||||
|
def after_request(response):
|
||||||
|
# This forbids other sites from embedding this site in an iframe,
|
||||||
|
# preventing clickjacking attacks.
|
||||||
|
response.headers['X-Frame-Options'] = 'DENY'
|
||||||
|
return response
|
||||||
|
|
||||||
@app.route('/')
|
@app.route('/')
|
||||||
def index():
|
def index():
|
||||||
return render_template(
|
return render_template(
|
||||||
|
|||||||
Reference in New Issue
Block a user