From ec00c27ca398b1360b6c199c7b0ccc1037548eef Mon Sep 17 00:00:00 2001 From: Olivier Dony Date: Wed, 1 Nov 2017 21:41:24 +0100 Subject: [PATCH] [FIX] auth_signup: correct leftover from 6d16915d397db3d92795a19800f697226dcbc75 The /web/signup controller was also supposed to get the special frame header, like all sign-in/up pages. --- addons/auth_signup/controllers/main.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/addons/auth_signup/controllers/main.py b/addons/auth_signup/controllers/main.py index dcaba89bc61..ffea162a563 100644 --- a/addons/auth_signup/controllers/main.py +++ b/addons/auth_signup/controllers/main.py @@ -40,7 +40,9 @@ class AuthSignupHome(Home): _logger.error(e.message) qcontext['error'] = _("Could not create a new account.") - return request.render('auth_signup.signup', qcontext) + response = request.render('auth_signup.signup', qcontext) + response.headers['X-Frame-Options'] = 'DENY' + return response @http.route('/web/reset_password', type='http', auth='public', website=True) def web_auth_reset_password(self, *args, **kw):