Security: Add new setting allow_embedding (#16853)

When allow_embedding is false (default) the Grafana backend 
will set the http header `X-Frame-Options: deny` in all responses 
to non-static content which will instruct browser to not allow 
Grafana to be embedded in `<frame>`, `<iframe>`, 
`<embed>` or `<object>`.

Closes #14189
This commit is contained in:
Marcus Efraimsson
2019-05-06 09:56:23 +02:00
committed by GitHub
parent 44e6da6b41
commit 1c1427520d
7 changed files with 43 additions and 1 deletions
+3
View File
@@ -93,6 +93,7 @@ var (
DisableBruteForceLoginProtection bool
CookieSecure bool
CookieSameSite http.SameSite
AllowEmbedding bool
// Snapshots
ExternalSnapshotUrl string
@@ -690,6 +691,8 @@ func (cfg *Cfg) Load(args *CommandLineArgs) error {
cfg.CookieSameSite = CookieSameSite
}
AllowEmbedding = security.Key("allow_embedding").MustBool(false)
// read snapshots settings
snapshots := iniFile.Section("snapshots")
ExternalSnapshotUrl, err = valueAsString(snapshots, "external_snapshot_url", "")