Преглед на файлове

Fixed #24896 -- Doc'd clickjacking protection doesn't overwrite X-Frame-Options header.

Simeon J Morgan преди 9 години
родител
ревизия
0b5fb8e72c
променени са 1 файла, в които са добавени 3 реда и са изтрити 0 реда
  1. 3 0
      docs/ref/clickjacking.txt

+ 3 - 0
docs/ref/clickjacking.txt

@@ -45,6 +45,9 @@ site:
 2. A set of view decorators that can be used to override the middleware or to
    only set the header for certain views.
 
+The ``X-Frame-Options`` HTTP header will only be set by the middleware or view
+decorators if it is not already present in the response.
+
 How to use it
 =============