Preserve browser Origin on the confirmed sign-out form
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 35s
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 35s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
This commit is contained in:
parent
074c2ce498
commit
91efb6d988
2 changed files with 5 additions and 1 deletions
|
|
@ -47,7 +47,8 @@ Applications that already have their own sessions may remain signed in.</p>
|
|||
|
||||
func (h *AccountLogoutHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
|
||||
w.Header().Set("Cache-Control", "no-store")
|
||||
w.Header().Set("Referrer-Policy", "no-referrer")
|
||||
// Keep the same-origin POST Origin; no-referrer makes Chromium send Origin: null.
|
||||
w.Header().Set("Referrer-Policy", "same-origin")
|
||||
w.Header().Set("Content-Security-Policy", "default-src 'none'; form-action 'self'; frame-ancestors 'none'; base-uri 'none'")
|
||||
w.Header().Set("X-Content-Type-Options", "nosniff")
|
||||
switch r.Method {
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue