From 3e24b719cd2754117ec6f697d8f460e5f25331af Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Dawid=20Gawe=C5=82?= <daw.gawel@gmail.com> Date: Wed, 30 Dec 2015 14:18:00 +0100 Subject: [PATCH] XFrameOptionsMiddleware added XFrameOptionsMiddleware added to prevent clickjacking. X-Frame-Options set to default (SAMEORIGIN). --- settings.py | 1 + 1 file changed, 1 insertion(+) diff --git a/settings.py b/settings.py index f1e2ab2..ec3773b 100644 --- a/settings.py +++ b/settings.py @@ -118,6 +118,7 @@ MIDDLEWARE_CLASSES = ( # secure a bunch of things 'djangosecure.middleware.SecurityMiddleware', + 'django.middleware.clickjacking.XFrameOptionsMiddleware', 'django.middleware.common.CommonMiddleware', 'django.contrib.sessions.middleware.SessionMiddleware', -- GitLab