Quellcode durchsuchen

Fixed #30732 -- Doc'd that SameSite cookies flags can affect xframe_options_exempt.

Jezeniel Zapanta vor 5 Jahren
Ursprung
Commit
e8ad265ac8
1 geänderte Dateien mit 5 neuen und 0 gelöschten Zeilen
  1. 5 0
      docs/ref/clickjacking.txt

+ 5 - 0
docs/ref/clickjacking.txt

@@ -88,6 +88,11 @@ that tells the middleware not to set the header::
     def ok_to_load_in_a_frame(request):
         return HttpResponse("This page is safe to load in a frame on any site.")
 
+.. note::
+
+    If you want to submit a form or access a session cookie within a frame or
+    iframe, you may need to modify the :setting:`CSRF_COOKIE_SAMESITE` or
+    :setting:`SESSION_COOKIE_SAMESITE` settings.
 
 Setting ``X-Frame-Options`` per view
 ------------------------------------