Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build: prevent framing of dev app with X-Frame-Options #24651

Merged
merged 1 commit into from
Mar 23, 2022

Conversation

josephperrott
Copy link
Member

Prevent the dev app site from being place in an iframe.

Prevent the dev app site from being place in an iframe.
@josephperrott josephperrott added action: merge The PR is ready for merge by the caretaker merge safe target: patch This PR is targeted for the next patch release area: build & ci Related the build and CI infrastructure of the project labels Mar 23, 2022
@josephperrott josephperrott requested a review from a team as a code owner March 23, 2022 18:15
@josephperrott josephperrott added the dev-app preview When applied, previews of the dev-app are deployed to Firebase label Mar 23, 2022
@github-actions
Copy link

Copy link
Member

@devversion devversion left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, what's the context here?

@josephperrott
Copy link
Member Author

Good security policy to prevent being placed in an iframe, unless we want to allow it, which we don't have a use case for wanting.

@josephperrott josephperrott merged commit ed9260b into angular:master Mar 23, 2022
josephperrott added a commit that referenced this pull request Mar 23, 2022
Prevent the dev app site from being place in an iframe.

(cherry picked from commit ed9260b)
forsti0506 pushed a commit to forsti0506/components that referenced this pull request Apr 3, 2022
Prevent the dev app site from being place in an iframe.
@angular-automatic-lock-bot
Copy link

This issue has been automatically locked due to inactivity.
Please file a new issue if you are encountering a similar or related problem.

Read more about our automatic conversation locking policy.

This action has been performed automatically by a bot.

@angular-automatic-lock-bot angular-automatic-lock-bot bot locked and limited conversation to collaborators Apr 23, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
action: merge The PR is ready for merge by the caretaker area: build & ci Related the build and CI infrastructure of the project dev-app preview When applied, previews of the dev-app are deployed to Firebase target: patch This PR is targeted for the next patch release
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants