[PR #2547] [MERGED] [dashboard] Use X-Frame-Options sameorigin header #15296

Closed
opened 2026-08-05 03:07:22 -04:00 by saavagebueno · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/netbirdio/netbird/pull/2547
Author: @heisbrot
Created: 9/6/2024
Status: Merged
Merged: 9/6/2024
Merged by: @mlsmaycon

Base: mainHead: fix/x-frame-options


📝 Commits (1)

  • 8ce6e23 Use X-Frame-Options sameorigin header

📊 Changes

1 file changed (+1 additions, -1 deletions)

View changed files

📝 infrastructure_files/getting-started-with-zitadel.sh (+1 -1)

📄 Description

Describe your changes

The previous X-Frame DENY header prevented to display the page inside an iFrame.
The current OIDC library for the dashboard uses iFrame to perform a silent login.

Silent signing uses cookies from your OIDC provider to restore the session and retrieve tokens. It opens an IFrame in the background, directed to a specific page on your OIDC provider.

This fix changes the X-Frame-Options header DENY to SAMEORIGIN

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)
  • Extended the README / documentation, if necessary

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/netbirdio/netbird/pull/2547 **Author:** [@heisbrot](https://github.com/heisbrot) **Created:** 9/6/2024 **Status:** ✅ Merged **Merged:** 9/6/2024 **Merged by:** [@mlsmaycon](https://github.com/mlsmaycon) **Base:** `main` ← **Head:** `fix/x-frame-options` --- ### 📝 Commits (1) - [`8ce6e23`](https://github.com/netbirdio/netbird/commit/8ce6e231399515dc57323f87ad9b0fe822f4cc99) Use X-Frame-Options sameorigin header ### 📊 Changes **1 file changed** (+1 additions, -1 deletions) <details> <summary>View changed files</summary> 📝 `infrastructure_files/getting-started-with-zitadel.sh` (+1 -1) </details> ### 📄 Description ## Describe your changes The previous X-Frame DENY header prevented to display the page inside an iFrame. The current OIDC library for the dashboard uses iFrame to perform a silent login. > Silent signing uses cookies from your OIDC provider to restore the session and retrieve tokens. It opens an IFrame in the background, directed to a specific page on your OIDC provider. This fix changes the X-Frame-Options header `DENY` to `SAMEORIGIN` ## Issue ticket number and link ### Checklist - [x] Is it a bug fix - [ ] Is a typo/documentation fix - [ ] Is a feature enhancement - [ ] It is a refactor - [ ] Created tests that fail without the change (if possible) - [ ] Extended the README / documentation, if necessary --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
saavagebueno added the pull-request label 2026-08-05 03:07:22 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#15296