Skip to content

set X-Frame-Options#6302

Closed
math-GH wants to merge 3 commits intoFreshRSS:edgefrom
math-GH:better-security-headers
Closed

set X-Frame-Options#6302
math-GH wants to merge 3 commits intoFreshRSS:edgefrom
math-GH:better-security-headers

Conversation

@math-GH
Copy link
Contributor

@math-GH math-GH commented Apr 14, 2024

@math-GH math-GH added this to the 1.24.0 milestone Apr 14, 2024
@Alkarex
Copy link
Member

Alkarex commented Apr 14, 2024

This header seems obsolete

@Alkarex Alkarex modified the milestones: 1.24.0, 1.25.0 Apr 15, 2024
@math-GH
Copy link
Contributor Author

math-GH commented Apr 15, 2024

This header seems obsolete

As far as I understand it is obsolete if [frame-ancestors](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestors) is used.

Do you prefer to use it instead of the X-Frame-Options?

@Frenzie
Copy link
Member

Frenzie commented Apr 15, 2024

Yes, frame-ancestors is to be preferred afaict.

@math-GH math-GH marked this pull request as draft May 23, 2024 19:18
@Alkarex Alkarex modified the milestones: 1.25.0, 1.26.0 Nov 30, 2024
@math-GH math-GH closed this Jan 21, 2025
@Inverle Inverle mentioned this pull request Jun 18, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants