Security: Add new setting allow_embedding (#16853)
When allow_embedding is false (default) the Grafana backend will set the http header `X-Frame-Options: deny` in all responses to non-static content which will instruct browser to not allow Grafana to be embedded in `<frame>`, `<iframe>`, `<embed>` or `<object>`. Closes #14189
This commit is contained in:
@@ -93,6 +93,7 @@ var (
|
||||
DisableBruteForceLoginProtection bool
|
||||
CookieSecure bool
|
||||
CookieSameSite http.SameSite
|
||||
AllowEmbedding bool
|
||||
|
||||
// Snapshots
|
||||
ExternalSnapshotUrl string
|
||||
@@ -690,6 +691,8 @@ func (cfg *Cfg) Load(args *CommandLineArgs) error {
|
||||
cfg.CookieSameSite = CookieSameSite
|
||||
}
|
||||
|
||||
AllowEmbedding = security.Key("allow_embedding").MustBool(false)
|
||||
|
||||
// read snapshots settings
|
||||
snapshots := iniFile.Section("snapshots")
|
||||
ExternalSnapshotUrl, err = valueAsString(snapshots, "external_snapshot_url", "")
|
||||
|
||||
Reference in New Issue
Block a user