MyFaces Tobago
  1. MyFaces Tobago
  2. TOBAGO-1155

Prevent for Frame Attacks aka Clickjacking

    Details

    • Type: New Feature New Feature
    • Status: Closed
    • Priority: Minor Minor
    • Resolution: Fixed
    • Affects Version/s: 1.6.0-beta-1
    • Fix Version/s: 1.6.0-beta-2, 2.0.0
    • Component/s: Core, Themes
    • Labels:
      None

      Activity

      Hide
      Hudson added a comment -

      Integrated in tobago-trunk #1033 (See https://builds.apache.org/job/tobago-trunk/1033/)
      The prevent-frame-attacks now respect CSP

      See
      TOBAGO-1155: Prevent for Frame Attacks aka Clickjacking
      TOBAGO-1171: Support for the Content Security Policy (CSP) (Revision 1496839)

      Result = SUCCESS
      lofwyr : http://svn.apache.org/viewvc/?view=rev&rev=1496839
      Files :

      • /myfaces/tobago/trunk/tobago-example/tobago-example-test/src/main/webapp/WEB-INF/tobago-config.xml
      • /myfaces/tobago/trunk/tobago-theme/tobago-theme-scarborough/src/main/java/org/apache/myfaces/tobago/renderkit/html/scarborough/standard/tag/PageRenderer.java
      • /myfaces/tobago/trunk/tobago-theme/tobago-theme-scarborough/src/main/resources/org/apache/myfaces/tobago/renderkit/html/scarborough/standard/style/tobago.css
      • /myfaces/tobago/trunk/tobago-theme/tobago-theme-standard/src/main/resources/org/apache/myfaces/tobago/renderkit/html/standard/standard/script/tobago.js
      Show
      Hudson added a comment - Integrated in tobago-trunk #1033 (See https://builds.apache.org/job/tobago-trunk/1033/ ) The prevent-frame-attacks now respect CSP See TOBAGO-1155 : Prevent for Frame Attacks aka Clickjacking TOBAGO-1171 : Support for the Content Security Policy (CSP) (Revision 1496839) Result = SUCCESS lofwyr : http://svn.apache.org/viewvc/?view=rev&rev=1496839 Files : /myfaces/tobago/trunk/tobago-example/tobago-example-test/src/main/webapp/WEB-INF/tobago-config.xml /myfaces/tobago/trunk/tobago-theme/tobago-theme-scarborough/src/main/java/org/apache/myfaces/tobago/renderkit/html/scarborough/standard/tag/PageRenderer.java /myfaces/tobago/trunk/tobago-theme/tobago-theme-scarborough/src/main/resources/org/apache/myfaces/tobago/renderkit/html/scarborough/standard/style/tobago.css /myfaces/tobago/trunk/tobago-theme/tobago-theme-standard/src/main/resources/org/apache/myfaces/tobago/renderkit/html/standard/standard/script/tobago.js
      Hide
      Hudson added a comment -

      Integrated in tobago-trunk #840 (See https://builds.apache.org/job/tobago-trunk/840/)
      (TOBAGO-1155)
      Prevent for Frame Attacks aka Clickjacking
      without rendering javascript on page (Revision 1363833)

      Result = SUCCESS
      bommel : http://svn.apache.org/viewvc/?view=rev&rev=1363833
      Files :

      • /myfaces/tobago/trunk/tobago-theme/tobago-theme-scarborough/src/main/java/org/apache/myfaces/tobago/renderkit/html/scarborough/standard/tag/PageRenderer.java
      • /myfaces/tobago/trunk/tobago-theme/tobago-theme-standard/src/main/resources/org/apache/myfaces/tobago/renderkit/html/standard/standard/script/tobago.js
      Show
      Hudson added a comment - Integrated in tobago-trunk #840 (See https://builds.apache.org/job/tobago-trunk/840/ ) ( TOBAGO-1155 ) Prevent for Frame Attacks aka Clickjacking without rendering javascript on page (Revision 1363833) Result = SUCCESS bommel : http://svn.apache.org/viewvc/?view=rev&rev=1363833 Files : /myfaces/tobago/trunk/tobago-theme/tobago-theme-scarborough/src/main/java/org/apache/myfaces/tobago/renderkit/html/scarborough/standard/tag/PageRenderer.java /myfaces/tobago/trunk/tobago-theme/tobago-theme-standard/src/main/resources/org/apache/myfaces/tobago/renderkit/html/standard/standard/script/tobago.js
      Hide
      Hudson added a comment -

      Integrated in tobago-trunk #791 (See https://builds.apache.org/job/tobago-trunk/791/)
      (TOBAGO-1155)
      Prevent for Frame Attacks aka Clickjacking (Revision 1351664)

      Result = SUCCESS
      bommel : http://svn.apache.org/viewvc/?view=rev&rev=1351664
      Files :

      • /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/config/TobagoConfig.java
      • /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/internal/config/TobagoConfigBuilder.java
      • /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/internal/config/TobagoConfigFragment.java
      • /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/internal/config/TobagoConfigImpl.java
      • /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/internal/config/TobagoConfigParser.java
      • /myfaces/tobago/trunk/tobago-core/src/main/resources/org/apache/myfaces/tobago/config/tobago-config-1.6.xsd
      • /myfaces/tobago/trunk/tobago-example/tobago-example-test/src/main/webapp/WEB-INF/tobago-config.xml
      • /myfaces/tobago/trunk/tobago-theme/tobago-theme-scarborough/src/main/java/org/apache/myfaces/tobago/renderkit/html/scarborough/standard/tag/PageRenderer.java
      Show
      Hudson added a comment - Integrated in tobago-trunk #791 (See https://builds.apache.org/job/tobago-trunk/791/ ) ( TOBAGO-1155 ) Prevent for Frame Attacks aka Clickjacking (Revision 1351664) Result = SUCCESS bommel : http://svn.apache.org/viewvc/?view=rev&rev=1351664 Files : /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/config/TobagoConfig.java /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/internal/config/TobagoConfigBuilder.java /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/internal/config/TobagoConfigFragment.java /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/internal/config/TobagoConfigImpl.java /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/internal/config/TobagoConfigParser.java /myfaces/tobago/trunk/tobago-core/src/main/resources/org/apache/myfaces/tobago/config/tobago-config-1.6.xsd /myfaces/tobago/trunk/tobago-example/tobago-example-test/src/main/webapp/WEB-INF/tobago-config.xml /myfaces/tobago/trunk/tobago-theme/tobago-theme-scarborough/src/main/java/org/apache/myfaces/tobago/renderkit/html/scarborough/standard/tag/PageRenderer.java
      Hide
      Hudson added a comment -

      Integrated in tobago-trunk #789 (See https://builds.apache.org/job/tobago-trunk/789/)
      (TOBAGO-1155)
      Prevent for Frame Attacks aka Clickjacking (Revision 1351664)

      Result = FAILURE
      bommel : http://svn.apache.org/viewvc/?view=rev&rev=1351664
      Files :

      • /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/config/TobagoConfig.java
      • /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/internal/config/TobagoConfigBuilder.java
      • /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/internal/config/TobagoConfigFragment.java
      • /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/internal/config/TobagoConfigImpl.java
      • /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/internal/config/TobagoConfigParser.java
      • /myfaces/tobago/trunk/tobago-core/src/main/resources/org/apache/myfaces/tobago/config/tobago-config-1.6.xsd
      • /myfaces/tobago/trunk/tobago-example/tobago-example-test/src/main/webapp/WEB-INF/tobago-config.xml
      • /myfaces/tobago/trunk/tobago-theme/tobago-theme-scarborough/src/main/java/org/apache/myfaces/tobago/renderkit/html/scarborough/standard/tag/PageRenderer.java
      Show
      Hudson added a comment - Integrated in tobago-trunk #789 (See https://builds.apache.org/job/tobago-trunk/789/ ) ( TOBAGO-1155 ) Prevent for Frame Attacks aka Clickjacking (Revision 1351664) Result = FAILURE bommel : http://svn.apache.org/viewvc/?view=rev&rev=1351664 Files : /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/config/TobagoConfig.java /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/internal/config/TobagoConfigBuilder.java /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/internal/config/TobagoConfigFragment.java /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/internal/config/TobagoConfigImpl.java /myfaces/tobago/trunk/tobago-core/src/main/java/org/apache/myfaces/tobago/internal/config/TobagoConfigParser.java /myfaces/tobago/trunk/tobago-core/src/main/resources/org/apache/myfaces/tobago/config/tobago-config-1.6.xsd /myfaces/tobago/trunk/tobago-example/tobago-example-test/src/main/webapp/WEB-INF/tobago-config.xml /myfaces/tobago/trunk/tobago-theme/tobago-theme-scarborough/src/main/java/org/apache/myfaces/tobago/renderkit/html/scarborough/standard/tag/PageRenderer.java

        People

        • Assignee:
          Bernd Bohmann
          Reporter:
          Bernd Bohmann
        • Votes:
          0 Vote for this issue
          Watchers:
          2 Start watching this issue

          Dates

          • Created:
            Updated:
            Resolved:

            Development