Quantcast
Channel: Zammad - Community - Latest posts
Viewing all articles
Browse latest Browse all 6760

CSRF TOKEN while using I-Frame

$
0
0

Hi @SaifNeon,

to prevent Cross Site Request Forgery attacks as described in your scenario, we set the header X-Frame-Options: SAMEORIGIN. The iframe you are using does not match the allowed origin.

This is a security feature and will not be broken.

Cheers,

Tobias


Viewing all articles
Browse latest Browse all 6760

Trending Articles