Allow qr code iframe

Signed-off-by: Christian König <ckoenig@posteo.de>
This commit is contained in:
Christian König 2021-12-10 07:17:13 +01:00
parent 8d6ce78c65
commit 2eff53b2bb
No known key found for this signature in database
GPG key ID: 4CDA6F249DD2B485
2 changed files with 8 additions and 4 deletions

View file

@ -93,8 +93,10 @@ $HTTP["url"] =~ "/teleporter\.php$" {
}
# allow API qr code iframe on settings page
$HTTP["url"] =~ "/admin/settings\.php$" {
setenv.add-response-header = ( "X-Frame-Options" => "SAMEORIGIN" )
$HTTP["url"] =~ "/api_token\.php$" {
$HTTP["referer"] =~ "/admin/settings\.php" {
setenv.add-response-header = ( "X-Frame-Options" => "SAMEORIGIN" )
}
}
# Default expire header

View file

@ -101,8 +101,10 @@ $HTTP["url"] =~ "/teleporter\.php$" {
}
# allow API qr code iframe on settings page
$HTTP["url"] =~ "/admin/settings\.php$" {
setenv.add-response-header = ( "X-Frame-Options" => "SAMEORIGIN" )
$HTTP["url"] =~ "/api_token\.php$" {
$HTTP["referer"] =~ "/admin/settings\.php" {
setenv.add-response-header = ( "X-Frame-Options" => "SAMEORIGIN" )
}
}
# Default expire header