GirlsCodeLincoln / Website

The Girls Code Lincoln website
https://girlscodelincoln.org
5 stars 1 forks source link

Stop Click Jacking #96

Closed benweese closed 5 years ago

benweese commented 5 years ago

Click Jacking is when someone puts your site in an iFrame and then puts hidden elements over your elements. An example would be if someone bought girlscodelincoln.org and then added a element over the submit button that would look to see if they are logged into their bank account and then it could transfer money that way.

justinjstark commented 5 years ago

This looks good. I don't see the HTTP headers in the Netlify deploy preview: https://5db86b10356c9b00087bc610--girlscodelincoln.netlify.com/ But that could be an issue with Netlify. The syntax looks like it does in the docs so I think it's good and won't break anything if it's wrong. https://docs.netlify.com/routing/headers/#syntax-for-the-netlify-configuration-file

benweese commented 5 years ago

I tested this with the deployment url and messaged in chat. Merging in.