Support

Admin Tools

#25510 X-Frame-options

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Sunday, 31 July 2016 17:20 CDT

menolo
Hi guys,

I just read ticket #25436. I can't seem to reply to that ticket but I ran into something related.

I want to show a certain page of my website in an iframe. This page has it's own clean joomla template without any of our corporate style or visual identity in it. There's just clean, unstyled html ourput.

When I:
- disable the X-frame-options in Admin tools and
- set the X-frame-origins header with PHP for my default corporate template
- do not set this header with PHP in the other template
- blocked using ?tmpl in the querystring with admin tools

At least then I have some sort of mediocre solution to avoid clickjacking for our official looking webpages. Only the other basic template can be iframed.

At least untill Chrome and Safari properly support X-frame-origin.

Would this be better than nothing, you think?

Regards,

Wim

nicholas
Akeeba Staff
Manager
It's better than nothing but it is not a solution against click jacking. As long as someone can present your page inside an IFRAME they can abuse that power for click jacking. It is a problem that didn't exist when IFRAMES were introduced about 19 years ago. Basically, it is what it is. Not much anything else you can do :(

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!