From 884d648cc2d1e6c0e4fecb771427a6524f96ce1d Mon Sep 17 00:00:00 2001 From: Jeremy Stretch Date: Thu, 9 Apr 2020 15:31:18 -0400 Subject: [PATCH] Set X_FRAME_OPTIONS to SAMEORIGIN (changed in Django 3.0) --- netbox/netbox/settings.py | 1 + 1 file changed, 1 insertion(+) diff --git a/netbox/netbox/settings.py b/netbox/netbox/settings.py index a6a55cf4b..87e584b69 100644 --- a/netbox/netbox/settings.py +++ b/netbox/netbox/settings.py @@ -345,6 +345,7 @@ USE_TZ = True WSGI_APPLICATION = 'netbox.wsgi.application' SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https') USE_X_FORWARDED_HOST = True +X_FRAME_OPTIONS = 'SAMEORIGIN' # Static files (CSS, JavaScript, Images) STATIC_ROOT = BASE_DIR + '/static'