|Site customization: $wgEditPageFrameOptions|
|Control framing of wiki pages globally.|
|Introduced in version:||1.16.1|
|Removed in version:||still in use|
|Other settings: Alphabetical | By function|
This variable determines the
X-Frame-Options header to send on pages sensitive to clickjacking attacks, such as edit pages.
This prevents those pages from being displayed in a frame or iframe.
The options are:
- Do not allow framing. This is recommended for most wikis.
- Allow framing by pages on the same domain. This can be used to allow framing within a trusted domain. This is insecure if there is a page on the same domain which allows framing of arbitrary URLs.
- Allow all framing. This opens up the wiki to XSS attacks and thus full compromise of local user accounts. Private wikis behind a corporate firewall are especially vulnerable. This is not recommended.