From: Tim Starling Date: Tue, 4 Jan 2011 06:12:33 +0000 (+0000) Subject: Fix for bug 26561: clickjacking attacks. See the bug report for full documentation. X-Git-Tag: 1.31.0-rc.0~32832 X-Git-Url: http://git.cyclocoop.org/%24self?a=commitdiff_plain;h=ccfe5ad97b2d4dce3f6214cc8826ae9a2c0d80fb;p=lhc%2Fweb%2Fwiklou.git Fix for bug 26561: clickjacking attacks. See the bug report for full documentation. --- diff --git a/includes/Article.php b/includes/Article.php index 3355b0138d..3b7780fe5a 100644 --- a/includes/Article.php +++ b/includes/Article.php @@ -886,6 +886,9 @@ class Article { return; } + # Allow frames by default + $wgOut->allowClickjacking(); + if ( !$wgUseETag && !$this->mTitle->quickUserCan( 'edit' ) ) { $parserOptions->setEditSection( false ); } @@ -1304,6 +1307,7 @@ class Article { $sk = $wgUser->getSkin(); $token = $wgUser->editToken( $rcid ); + $wgOut->preventClickjacking(); $wgOut->addHTML( "