calmPress / calmpress

A modern CMS based on WordPress
https://calmpress.org/
22 stars 1 forks source link

Prevent embedding any page of the site in an iframe on a different site #330

Closed markkap closed 3 years ago

markkap commented 3 years ago

Right now only login page and the admin screen are prevented, which is a simplistic view on how login and admin functionalities works since they can be exposed via ajax/rest APIs without being on a proper login/admin page.

markkap commented 3 years ago

not as simple as hoped, ended adding additional case for "front end" html generation as having one header set of the whole site resulted in "headers sent" type of error during testing which requires too much effort to properly resolve.