Skip to content

Commit 7930c78

Browse files
committed
2.12.14 Add headers for Cross-Origin-Opener-Policy
1 parent 73d6a09 commit 7930c78

File tree

3 files changed

+10
-2
lines changed

3 files changed

+10
-2
lines changed

src/includes/constants.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
/* ------------------------------------------
33
* @VERSION
44
* ------------------------------------------*/
5-
$C_VERSION = "2.12.3";
5+
$C_VERSION = "2.12.4";
66
$C_VERSION_STRING = "Version: " . $C_VERSION;
77
$C_MAX_HINT_LEVEL = 1;
88

src/index.php

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -303,6 +303,10 @@ function handleException(){
303303
/* Referrer Policy */
304304
header("Referrer-Policy: unsafe-url", true);
305305

306+
/* Anti-Tab Nabbing headers */
307+
header("Cross-Origin-Opener-Policy: unsafe-none");
308+
header_remove("Cross-Origin-Embedder-Policy");
309+
306310
header_remove("Pragma");
307311

308312
/* Content sniffing */
@@ -336,6 +340,10 @@ function handleException(){
336340
/* Referrer Policy */
337341
header("Referrer-Policy: no-referrer", true);
338342

343+
// Anti-Tab Nabbing headers
344+
header("Cross-Origin-Opener-Policy: same-origin");
345+
header("Cross-Origin-Embedder-Policy: require-corp");
346+
339347
/* Server version banners */
340348
header_remove("X-Powered-By");
341349
header_remove("Server");

version

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
2.12.3
1+
2.12.4

0 commit comments

Comments
 (0)