Skip to content

fix: prevent clickjacking with X-Frame-Options - #2239

Merged
bosbaber merged 1 commit into
mainfrom
miruna/int1-683
Sep 16, 2026
Merged

bosbaber merged 1 commit into
mainfrom
miruna/int1-683

Conversation

@mirunagherman

@mirunagherman mirunagherman commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Context

  • fixes INT1-683 - Findings from the security audit - Missing or Misconfigured X-Frame-Options Header

Changes

  • Prevent the application from being embedded in iframes by adding X-Frame-Options: DENY and a CSP frame-ancestors 'none' directive to responses.

@mirunagherman mirunagherman self-assigned this Sep 15, 2026
@github-actions github-actions Bot added package: wallet/frontend Wallet frontend implementations type: source Source changes labels Sep 15, 2026
@mirunagherman
mirunagherman marked this pull request as ready for review September 15, 2026 07:56
@bosbaber
bosbaber merged commit 868cf2f into main Sep 16, 2026
15 checks passed
@bosbaber
bosbaber deleted the miruna/int1-683 branch September 16, 2026 11:55
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

🎉 This PR is included in version 0.10.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

package: wallet/frontend Wallet frontend implementations released type: source Source changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants