Make WordPress Core


Ignore:
Timestamp:
05/06/2011 09:28:53 PM (12 years ago)
Author:
ryan
Message:

Send X-Frame-Options: SAMEORIGIN for admin and login pages. see #12293

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-includes/default-filters.php

    r17785 r17826  
    216216add_action( 'login_head',          'wp_print_head_scripts',         9     );
    217217add_action( 'login_footer',        'wp_print_footer_scripts'              );
     218add_action( 'login_form',          'send_frame_options_header',     10, 0 );
    218219
    219220// Feed Generator Tags
     
    249250add_action( 'before_wp_tiny_mce',         'wp_print_editor_js'             );
    250251add_action( 'after_wp_tiny_mce',          'wp_preload_dialogs',      10, 1 );
     252add_action( 'admin_init',                 'send_frame_options_header', 10, 0 );
    251253
    252254// Navigation menu actions
Note: See TracChangeset for help on using the changeset viewer.