src/main/java/com/gitblit/wicket/pages/BasePage.java
@@ -98,6 +98,10 @@ } } protected String getContextUrl() { return getRequest().getRelativePathPrefixToContextRoot(); } protected String getCanonicalUrl() { return getCanonicalUrl(getClass(), getPageParameters()); } @@ -162,6 +166,9 @@ // use default Wicket caching behavior super.setHeaders(response); } // XRF vulnerability. issue-500 / ticket-166 response.setHeader("X-Frame-Options", "SAMEORIGIN"); } /**