From b0f1f8307dc9bd1770f71d11e42e740a6e6b3d8b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tomasz=20Drwi=C4=99ga?= Date: Mon, 10 Jul 2017 09:42:35 +0200 Subject: [PATCH] X-Frame-Options removed. --- devtools/src/http_client.rs | 7 +------ 1 file changed, 1 insertion(+), 6 deletions(-) diff --git a/devtools/src/http_client.rs b/devtools/src/http_client.rs index 29a6d9c7c..078c33721 100644 --- a/devtools/src/http_client.rs +++ b/devtools/src/http_client.rs @@ -102,12 +102,7 @@ pub fn request(address: &SocketAddr, request: &str) -> Response { /// Check if all required security headers are present pub fn assert_security_headers_present(headers: &[String], port: Option) { - if let Some(port) = port { - assert!( - headers.iter().find(|header| header.as_str() == &format!("X-Frame-Options: ALLOW-FROM http://127.0.0.1:{}", port)).is_some(), - "X-Frame-Options: ALLOW-FROM missing: {:?}", headers - ); - } else { + if let None = port { assert!( headers.iter().find(|header| header.as_str() == "X-Frame-Options: SAMEORIGIN").is_some(), "X-Frame-Options: SAMEORIGIN missing: {:?}", headers