Jump to content

Manual:$wgApiFrameOptions

From mediawiki.org
This page is a translated version of the page Manual:$wgApiFrameOptions and the translation is 44% complete.
セキュリティ: $wgApiFrameOptions
API ページのフレーミングを制御します。
導入されたバージョン:1.20.0 (Gerrit change 20472; git #32b99b11)
除去されたバージョン:使用中
許容される値:(文字列) または false
既定値:'DENY'

詳細

Disallow framing of API pages directly, by setting the X-Frame-Options header. Since the API returns CSRF tokens, allowing the results to be framed can compromise your user's account security.

選択肢は以下の通りです:

'DENY'
Do not allow framing. This is recommended for most wikis.
'SAMEORIGIN'
Allow framing by pages on the same domain. This can be used to allow framing within a trusted origin. This is insecure if there is a page on the same origin that allows framing of arbitrary URLs.
false
フレーム化をすべて許可します。 This opens up the wiki to XSS attacks and thus full compromise of local user accounts. Private wikis behind a corporate firewall are especially vulnerable. This is not recommended.

関連項目