mirror of
				https://github.com/django/django.git
				synced 2025-10-26 15:16:09 +00:00 
			
		
		
		
	[1.8.x] Fixed #24896 -- Doc'd clickjacking protection doesn't overwrite X-Frame-Options header.
Backport of 0b5fb8e72c from master
			
			
This commit is contained in:
		
				
					committed by
					
						 Tim Graham
						Tim Graham
					
				
			
			
				
	
			
			
			
						parent
						
							aefa3a6a03
						
					
				
				
					commit
					3b41850adc
				
			| @@ -45,6 +45,9 @@ site: | ||||
| 2. A set of view decorators that can be used to override the middleware or to | ||||
|    only set the header for certain views. | ||||
|  | ||||
| The ``X-Frame-Options`` HTTP header will only be set by the middleware or view | ||||
| decorators if it is not already present in the response. | ||||
|  | ||||
| How to use it | ||||
| ============= | ||||
|  | ||||
|   | ||||
		Reference in New Issue
	
	Block a user