baikal/Core
Frederic Hemberger 4ca925874c Improve application security
- Make session cookies only available via HTTP (prevent access from JavaScript)
- only log PHP errors instead of displaying them in production.
  Displaying errors may give attackers hints how to exploit the application

Set HTTP headers:

X-Frame-Options: DENY
Prevent Clickjacking attacks, see: http://en.wikipedia.org/wiki/Clickjacking

X-Content-Type-Options: nosniff
Prevent code injection via mime type sniffing
2014-01-21 16:14:47 +01:00
..
Frameworks Improve application security 2014-01-21 16:14:47 +01:00
Resources Corrected a typo in MySQL SQL file 2013-07-07 23:35:06 +02:00
Distrib.php Bumped revision to 0.2.6 2013-07-07 23:37:08 +02:00