DNN Forums

Ask questions about your website to get help learning DNN and help resolve issues.

Change Login on theme

 4 Replies
 3 Subscribed to this topic
 11 Subscribed to this forum
Sort:
Author
Messages
New Around Here
Posts: 7
New Around Here

    Hi, we have a site that we have recently noticed that is it vulnerable to clickjacking. To fix this we we're looking at denying xframes from working on the site but when we implement this the login box doesn't work as this is in a model I beleive using an iframe. We were thinking of changing the login to be inline instead of in a model does anyone know how to do this please?

     

    Thank you

    Brian

    Veteran Member
    Posts: 743
    Veteran Member

      Settings - Site settings - Site behavior - More  - Turn off Enable popups  

      Advanced Member
      Posts: 218
      Advanced Member

        You can create a Login Page and place the login control that comes within DNN; also make sure that you specify the login page at "Site Settings -> Site Behavior -> Default Pages"

        Senior Member
        Posts: 1362
        Senior Member
          Posted By Tycho de Waard (SU) on 5/5/2023 6:41 AM

          Settings - Site settings - Site behavior - More  - Turn off Enable popups  

          I'd have to echo Tycho's suggestion.  This is not only for this specific use case, but the pop-ups in general don't seem to add any value for any of our clients.  It's simply in the way all of the time.  Most end-users are quite annoyed by that UX.  

           

          Veteran Member
          Posts: 1158
          Veteran Member

            You can also set the X-Frame-Options to SAMEORIGIN, this would allow IFrames with sources on your site - and you can still popup modals.

            Anyway, controlling the frame access in a CSP makes more sense, as you have more options. See CSP: frame-ancestors - HTTP | MDN (mozilla.org) for details.

            Happy DNNing!
            Michael

            Michael Tobisch
            DNN★MVP

            dnnWerk Austria
            DNN Connect

            These Forums are dedicated to the discussion of DNN Platform.

            For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

            1. If you have (suspected) security issues, please DO NOT post them in the forums but instead follow the official DNN security policy
            2. No Advertising. This includes the promotion of commercial and non-commercial products or services which are not directly related to DNN.
            3. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
            4. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
            5. No Flaming or Trolling.
            6. No Profanity, Racism, or Prejudice.
            7. Site Moderators have the final word on approving / removing a thread or post or comment.
            8. English language posting only, please.

            Would you like to help us?

            Awesome! Simply post in the forums using the link below and we'll get you started.

            Get Involved