[Webkit-unassigned] [Bug 23907] New: Implement X-Frame-Options

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Wed Feb 11 17:30:12 PST 2009


https://bugs.webkit.org/show_bug.cgi?id=23907

           Summary: Implement X-Frame-Options
           Product: WebKit
           Version: 528+ (Nightly build)
          Platform: All
               URL: http://blogs.msdn.com/ie/archive/2009/01/27/ie8-
                    security-part-vii-clickjacking-defenses.aspx
        OS/Version: All
            Status: NEW
          Severity: Normal
          Priority: P2
         Component: Frames
        AssignedTo: webkit-unassigned at lists.webkit.org
        ReportedBy: abarth at webkit.org


We should implement X-Frame-Options to help sites defend against ClickJacking. 
Here is a blog post describing the feature:

http://blogs.msdn.com/ie/archive/2009/01/27/ie8-security-part-vii-clickjacking-defenses.aspx

I'm not sure this completely solves the ClickJacking problem, but it certainly
does more good than harm.  I can ask Eric Lawrence for a more detailed design
doc if we want to make sure we match IE's behavior.

Here is the Mozilla bug on this topic:

https://bugzilla.mozilla.org/show_bug.cgi?id=475530

dveditz seems similarly positively disposed to implementing this feature.


-- 
Configure bugmail: https://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.



More information about the webkit-unassigned mailing list