Re: [Freeipa-devel] [PATCH] 0008 Add X-Frame-Options and frame-ancestors options

2016-04-15 Thread Petr Vobornik
On 03/11/2016 10:20 AM, Pavel Vomacka wrote: > > > On 03/11/2016 09:25 AM, Petr Vobornik wrote: >> On 03/10/2016 07:22 PM, Simo Sorce wrote: >>> On Thu, 2016-03-10 at 19:20 +0100, Pavel Vomacka wrote: On 03/10/2016 07:02 PM, Simo Sorce wrote: > On Thu, 2016-03-10 at 18:47 +0100,

Re: [Freeipa-devel] [PATCH] 0008 Add X-Frame-Options and frame-ancestors options

2016-03-11 Thread Pavel Vomacka
On 03/11/2016 09:25 AM, Petr Vobornik wrote: On 03/10/2016 07:22 PM, Simo Sorce wrote: On Thu, 2016-03-10 at 19:20 +0100, Pavel Vomacka wrote: On 03/10/2016 07:02 PM, Simo Sorce wrote: On Thu, 2016-03-10 at 18:47 +0100, Pavel Vomacka wrote: Hi, These two options allow preventing

Re: [Freeipa-devel] [PATCH] 0008 Add X-Frame-Options and frame-ancestors options

2016-03-11 Thread Petr Vobornik
On 03/10/2016 07:22 PM, Simo Sorce wrote: On Thu, 2016-03-10 at 19:20 +0100, Pavel Vomacka wrote: On 03/10/2016 07:02 PM, Simo Sorce wrote: On Thu, 2016-03-10 at 18:47 +0100, Pavel Vomacka wrote: Hi, These two options allow preventing clickjacking attacks. They don't allow open FreeIPA in

Re: [Freeipa-devel] [PATCH] 0008 Add X-Frame-Options and frame-ancestors options

2016-03-10 Thread Simo Sorce
On Thu, 2016-03-10 at 19:20 +0100, Pavel Vomacka wrote: > > On 03/10/2016 07:02 PM, Simo Sorce wrote: > > On Thu, 2016-03-10 at 18:47 +0100, Pavel Vomacka wrote: > >> Hi, > >> > >> These two options allow preventing clickjacking attacks. They don't > >> allow open FreeIPA in frame, iframe or

Re: [Freeipa-devel] [PATCH] 0008 Add X-Frame-Options and frame-ancestors options

2016-03-10 Thread Pavel Vomacka
On 03/10/2016 07:02 PM, Simo Sorce wrote: On Thu, 2016-03-10 at 18:47 +0100, Pavel Vomacka wrote: Hi, These two options allow preventing clickjacking attacks. They don't allow open FreeIPA in frame, iframe or object element. Will these apply to the whole server or just to /ipa ? Yes, you

Re: [Freeipa-devel] [PATCH] 0008 Add X-Frame-Options and frame-ancestors options

2016-03-10 Thread Simo Sorce
On Thu, 2016-03-10 at 18:47 +0100, Pavel Vomacka wrote: > Hi, > > These two options allow preventing clickjacking attacks. They don't > allow open FreeIPA in frame, iframe or object element. Will these apply to the whole server or just to /ipa ? Simo. -- Simo Sorce * Red Hat, Inc * New York

[Freeipa-devel] [PATCH] 0008 Add X-Frame-Options and frame-ancestors options

2016-03-10 Thread Pavel Vomacka
Hi, These two options allow preventing clickjacking attacks. They don't allow open FreeIPA in frame, iframe or object element. -- Pavel^3 Vomacka >From c5a92092d87b3afeeaae0c37ce2bf8e892b9be84 Mon Sep 17 00:00:00 2001 From: Pavel Vomacka Date: Thu, 10 Mar 2016 18:32:50