Fix: revert removed x-frame-options header in non-debug

This commit is contained in:
shamoon 2025-03-24 07:28:27 -07:00 committed by GitHub
parent a8de26f88a
commit 5db511afdf
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -549,6 +549,9 @@ def _parse_remote_user_settings() -> str:
HTTP_REMOTE_USER_HEADER_NAME = _parse_remote_user_settings()
# X-Frame options for embedded PDF display:
X_FRAME_OPTIONS = "SAMEORIGIN"
# The next 3 settings can also be set using just PAPERLESS_URL
CSRF_TRUSTED_ORIGINS = __get_list("PAPERLESS_CSRF_TRUSTED_ORIGINS")