HTTP Header Frame Options
draft-ietf-websec-frame-options-00
Document | Type | Expired Internet-Draft (websec WG) | |
---|---|---|---|
Last updated | 2013-01-07 (latest revision 2012-07-06) | ||
Replaces | draft-gondrom-frame-options | ||
Stream | IETF | ||
Intended RFC status | (None) | ||
Formats |
Expired & archived
pdf
htmlized
bibtex
|
||
Stream | WG state | Parked WG Document | |
Document shepherd | No shepherd assigned | ||
IESG | IESG state | Expired | |
Consensus Boilerplate | Unknown | ||
Telechat date | |||
Responsible AD | (None) | ||
Send notices to | (None) |
https://www.ietf.org/archive/id/draft-ietf-websec-frame-options-00.txt
Abstract
To improve the protection of web applications against Clickjacking this standards defines a http response header that declares a policy communicated from a host to the client browser whether the transmitted content MUST NOT be displayed in frames of other pages from different origins which are allowed to frame the content.
Authors
David Ross
Tobias Gondrom
(tobias.gondrom@gondrom.org)
(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)