Content-Security-Policy and X-Frame-Options header config in http://antispam.csu.edu.au:32224/?dmVyPTEuMDAxJiY0YzA0ZThiMjA1NmJhYTkyNT01QzM3QjFEOV81NzM5OF84Nzk1XzEmJmZiNjI0N2U4ODdhYTNmZD0xMzMzJiZ1cmw9aWRwJTJFcHJvcGVydGllcw==

Cantor, Scott cantor.2 at osu.edu
Thu Jan 10 17:33:26 EST 2019


On 1/10/19, 5:28 PM, "users on behalf of Losen, Stephen C (scl)" <users-bounces at shibboleth.net on behalf of scl at virginia.edu> wrote:

> In browser "developer" mode I definitely saw two X-Frame-Options headers and two Content-Security-Policy headers
> coming from the IDP, so I guess "last header wins?"

I can't reproduce that, so I don't know what to tell you. If it's Tomcat, then I'd rule that out. It does not physically do that in the code, it's a map with one entry per header name and if you're not supplying your own map object there's no way you could get the code to send two just by setting properties.

-- Scott




More information about the users mailing list