......@@ -143,6 +143,8 @@ public class Handler extends AbstractHandler
// User is now logged in with a valid sesion.
// We set the session cookie to keep the user logged in:
response.addCookie(new Cookie("session",session.identity.toString()));
// Set X-Frame-Options header
response.setHeader("X-Frame-Options", "SAMEORIGIN");
final PrintWriter out = response.getWriter();
// Handle a logged in request.
