Skip to content

SEC-2098: X-Frame-Options to defend against clickjacking #2329

Closed
@spring-projects-issues

Description

@spring-projects-issues

Marten Deinum (Migrated from SEC-2098) said:

Although a clickjacking filter is simple to implement it would be nice if spring security provided one out of the box with an easy way of configuring.

<sec:clickjack mode="deny" />
or
<sec:clickjack mode="sameorigin" />

Metadata

Metadata

Assignees

Labels

in: webAn issue in web modules (web, webmvc)type: jiraAn issue that was migrated from JIRA

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions