Commit 3b41850a authored by Simeon J Morgan's avatar Simeon J Morgan Committed by Tim Graham
Browse files

[1.8.x] Fixed #24896 -- Doc'd clickjacking protection doesn't overwrite X-Frame-Options header.

Backport of 0b5fb8e7 from master
parent aefa3a6a
Loading
Loading
Loading
Loading
+3 −0
Original line number Diff line number Diff line
@@ -45,6 +45,9 @@ site:
2. A set of view decorators that can be used to override the middleware or to
   only set the header for certain views.

The ``X-Frame-Options`` HTTP header will only be set by the middleware or view
decorators if it is not already present in the response.

How to use it
=============