mirror of
https://github.com/Alfresco/alfresco-community-repo.git
synced 2025-07-31 17:39:05 +00:00
MNT-22184 Add security header for admin console (#323)
This commit is contained in:
@@ -184,5 +184,15 @@
|
|||||||
</filter>
|
</filter>
|
||||||
|
|
||||||
</config>
|
</config>
|
||||||
|
<!--
|
||||||
|
A set of HTTP response headers that instructs the browser to behave in certain ways to improve security
|
||||||
|
-->
|
||||||
|
<config evaluator="string-compare" condition="SecurityHeadersPolicy">
|
||||||
|
<headers>
|
||||||
|
<header>
|
||||||
|
<name>X-Frame-Options</name>
|
||||||
|
<value>SAMEORIGIN</value>
|
||||||
|
</header>
|
||||||
|
</headers>
|
||||||
|
</config>
|
||||||
</alfresco-config>
|
</alfresco-config>
|
@@ -104,6 +104,12 @@
|
|||||||
<filter-class>org.springframework.extensions.webscripts.servlet.CSRFFilter</filter-class>
|
<filter-class>org.springframework.extensions.webscripts.servlet.CSRFFilter</filter-class>
|
||||||
</filter>
|
</filter>
|
||||||
|
|
||||||
|
<filter>
|
||||||
|
<description>Security Headers filter. Adds security response headers based on config.</description>
|
||||||
|
<filter-name>Security Headers Filter</filter-name>
|
||||||
|
<filter-class>org.springframework.extensions.webscripts.servlet.SecurityHeadersFilter</filter-class>
|
||||||
|
</filter>
|
||||||
|
|
||||||
<!-- Enterprise filter placeholder -->
|
<!-- Enterprise filter placeholder -->
|
||||||
<filter-mapping>
|
<filter-mapping>
|
||||||
<filter-name>Clear security context filter</filter-name>
|
<filter-name>Clear security context filter</filter-name>
|
||||||
@@ -225,6 +231,11 @@
|
|||||||
<url-pattern>/wcs/admin/*</url-pattern>
|
<url-pattern>/wcs/admin/*</url-pattern>
|
||||||
</filter-mapping>
|
</filter-mapping>
|
||||||
|
|
||||||
|
<filter-mapping>
|
||||||
|
<filter-name>Security Headers Filter</filter-name>
|
||||||
|
<url-pattern>/*</url-pattern>
|
||||||
|
</filter-mapping>
|
||||||
|
|
||||||
<!-- Enterprise filter-mapping placeholder -->
|
<!-- Enterprise filter-mapping placeholder -->
|
||||||
|
|
||||||
<!-- Spring Context Loader listener - can disable loading of context if runtime config changes are needed -->
|
<!-- Spring Context Loader listener - can disable loading of context if runtime config changes are needed -->
|
||||||
|
Reference in New Issue
Block a user