phpBB

Development Discussion Board

phpBB's testing ground of bleeding edge code
Advanced search

X-Frame-Options (response header) - security

Discuss the future of phpBB. It is still nesting in its mother's womb, but it will grow a little bigger each day. Participate in its design & planning here.

X-Frame-Options (response header) - security

Postby Posts » Tue Jan 11, 2011 10:47 pm

The X-Frame-Options HTTP response header can be used to indicate whether or not a browser should be allowed to render a page in a <frame> or <iframe>. Sites can use this to avoid clickjacking attacks, by ensuring that their content is not embedded into other sites.

https://developer.mozilla.org/en/the_x- ... nse_header

mediawiki is now using it:
https://bugzilla.wikimedia.org/show_bug.cgi?id=26561
http://lists.wikimedia.org/pipermail/me ... 00093.html

Browser compatibility
Browser Lowest version
Internet Explorer 8.0
Firefox (Gecko) 3.6.9 (1.9.2.9)
Opera 10.50
Safari 4.0
Chrome 4.1.249.1042
Posts
Registered User
 
Posts: 6
Joined: Thu Feb 05, 2009 6:16 pm

Re: X-Frame-Options (response header) - security

Postby Noxwizard » Tue Jan 11, 2011 11:50 pm

I can see its usefulness, but it would definitely need to be an option on the Security section of the ACP. A non-trivial amount of board owners operate their sites in frames, so we wouldn't want to alienate the users who integrate it with their site this way.
User avatar
Noxwizard
Support Team Leader
Support Team Leader
 
Posts: 115
Joined: Sun Dec 18, 2005 5:44 pm
Location: Texas

Re: X-Frame-Options (response header) - security

Postby naderman » Tue Jan 11, 2011 11:56 pm

Indeed, this is not something we can enforce for all boards. An option would be a possibility but if it's not important enough for us to enforce on all boards, why clutter the ACP with more options? And realistically how many admins would enable this? So I think my vote is a nay.
www.naderman.de
Move your forum to Forumatic - we'll take care of maintenance & spam
User avatar
naderman
Development Team Leader
Development Team Leader
 
Posts: 1649
Joined: Sun Jan 11, 2004 2:11 am
Location: Karlsruhe, Germany


Return to [4.x] Discussion

Who is online

Users browsing this forum: No registered users and 6 guests