Using some ui redressing like [1], our edit token can be stolen when it's shown on api result pages.
It would be good to respect $wgEditPageFrameOptions on api result pages that show an edit token, if possible.
[1] - http://blog.kotowicz.net/2011/07/cross-domain-content-extraction-with.html
Version: 1.19.1
Severity: normal