Files
codeql/csharp/ql/test/query-tests/Security Features/CWE-451/MissingXFrameOptions/CodeAddedHeader/MissingXFrameOptions.cs
2018-08-02 17:53:23 +01:00

22 lines
461 B
C#

// semmle-extractor-options: ${testdir}/../../../../../resources/stubs/System.Web.cs /r:System.Collections.Specialized.dll
using System;
using System.Web;
public class AddXFrameOptions : IHttpHandler
{
public void ProcessRequest(HttpContext ctx)
{
// GOOD: X-Frame-Options added
ctx.Response.AddHeader("X-Frame-Options", "DENY");
}
public bool IsReusable
{
get
{
return true;
}
}
}