##// END OF EJS Templates
Only allow iframe embedding on same origin.
rgbkrk -
Show More
@@ -39,6 +39,10 class AuthenticatedHandler(web.RequestHandler):
39 39
40 40 def set_default_headers(self):
41 41 headers = self.settings.get('headers', {})
42
43 if "X-Frame-Options" not in headers:
44 headers["X-Frame-Options"] = "SAMEORIGIN"
45
42 46 for header_name,value in headers.items() :
43 47 try:
44 48 self.set_header(header_name, value)
@@ -65,6 +65,8 class KernelAPITest(NotebookTestBase):
65 65 self.assertEqual(r.status_code, 201)
66 66 self.assertIsInstance(kern1, dict)
67 67
68 self.assertEqual(r.headers['x-frame-options'], "SAMEORIGIN")
69
68 70 # GET request
69 71 r = self.kern_api.list()
70 72 self.assertEqual(r.status_code, 200)
General Comments 0
You need to be logged in to leave comments. Login now