Content-Security-Policy and X-Frame-Options header config in http://antispam.csu.edu.au:32224/?dmVyPTEuMDAxJiY0YzA0ZThiMjA1NmJhYTkyNT01QzM3QjFEOV81NzM5OF84Nzk1XzEmJmZiNjI0N2U4ODdhYTNmZD0xMzMzJiZ1cmw9aWRwJTJFcHJvcGVydGllcw==
Cantor, Scott
cantor.2 at osu.edu
Thu Jan 10 17:33:26 EST 2019
On 1/10/19, 5:28 PM, "users on behalf of Losen, Stephen C (scl)" <users-bounces at shibboleth.net on behalf of scl at virginia.edu> wrote:
> In browser "developer" mode I definitely saw two X-Frame-Options headers and two Content-Security-Policy headers
> coming from the IDP, so I guess "last header wins?"
I can't reproduce that, so I don't know what to tell you. If it's Tomcat, then I'd rule that out. It does not physically do that in the code, it's a map with one entry per header name and if you're not supplying your own map object there's no way you could get the code to send two just by setting properties.
-- Scott
More information about the users
mailing list