ᨉᨙᨁᨁ URL ᨑᨗᨆᨘᨈ
0 / 0

ᨈᨙᨇᨙ URL ᨑᨗ ᨔᨕᨗᨉᨅ ᨄᨚᨒᨙ ᨆᨇᨘᨒᨕᨗ

ᨈᨙᨀᨊ S ᨄᨚᨒᨙ ᨁᨊᨗ ᨔᨕᨗᨉᨅ  ·  ? ᨄᨚᨒᨙ ᨅᨊᨘᨈ
ᨔᨗᨈᨘᨔ ᨙᨊᨙ ᨅᨗᨔ ᨆᨅᨒᨚᨀᨗ ᨄᨊᨙᨇᨒᨊ iframe. ᨒᨙᨇᨑᨊ ᨅᨗᨔ ᨆᨌᨘᨒ ᨀᨚᨔᨚ.

ᨅᨊᨘᨈ & ᨄᨙᨊᨙᨒᨙᨔᨕᨗᨊ ᨆᨔᨒ
ᨆᨁ ᨔᨗᨁ ᨔᨗᨈᨘᨔ ᨉᨙᨁᨁ ᨆᨙᨒᨚᨉᨗ
ᨆᨁ ᨒᨙᨇᨑᨊ ᨀᨚᨔᨚ?

ᨆᨙᨁ ᨔᨗᨈᨘᨔ ᨆᨅᨒᨚᨀᨗ ᨄᨊᨙᨇᨒᨊ iframe ᨆᨙᨒᨕᨒᨘᨗ HTTP header. ᨕᨙᨊᨙ ᨄᨗᨈᨘᨑ ᨀᨕᨆᨊ ᨄᨚᨒᨙ ᨆᨄᨒᨗᨊᨉᨘᨁᨗ clickjacking.

⚠ ᨅᨁᨙᨆᨊ ᨅᨒᨚᨀᨗᨑ ᨆᨍᨍᨗ

ᨔᨗᨈᨘᨔ ᨆᨀᨗᨑᨗ header ᨑᨗ ᨅᨑᨕᨘᨔᨑᨆᨘ: "ᨕᨍ ᨆᨈᨙᨇᨙ ᨕᨒᨙ." ᨅᨑᨕᨘᨔᨑᨊ ᨆᨄᨈᨘᨑᨘ → iframe ᨀᨚᨔᨚ.

Headerᨄᨊᨁᨑᨘ
X-Frame-Options: DENYᨅᨒᨚᨀᨗ ᨔᨗᨊᨗᨊ
X-Frame-Options: SAMEORIGINᨉᨚᨆᨙᨗᨊ ᨄᨉ ᨆᨊᨙ
CSP: frame-ancestors 'none'ᨅᨒᨚᨀᨗ ᨆᨚᨉᨙᨑᨊ
ᨀᨚᨇᨈᨗᨅᨗᨒᨗᨈᨔ
ᨔᨗᨈᨘᨔᨔᨈᨈᨘᨔ
Google, Gmail, GitHubᨑᨗᨅᨒᨚᨀᨗ
Facebook, X / Twitterᨑᨗᨅᨒᨚᨀᨗ
Wikipediaᨔᨅᨁᨗᨊ
ᨔᨗᨈᨘᨔ ᨄᨘᨑᨆᨘᨆᨍᨍᨗ ✓
ᨄᨑᨀᨀᨔ ᨑᨗᨒᨒᨙ / dashboardᨆᨍᨍᨗ ✓
ᨔᨗᨈᨘᨔ ᨔᨈᨈᨗᨔ / ᨉᨚᨀᨘᨆᨙᨊᨆᨍᨍᨗ ✓
ᨄᨕᨙᨔᨘᨗ ᨔᨗᨈᨘᨔᨆᨘ ᨆᨍᨍᨗ
✓ ᨑᨙᨀᨚᨆᨙᨊᨉᨔᨗ

ᨕᨈᨘᨑ frame-ancestors ᨄᨚᨒᨙ ᨆᨄᨔᨗᨈᨗᨊᨗ ᨀᨊ walkurls.com ᨆᨊᨙ.

Apache (.htaccess)
Header set Content-Security-Policy "frame-ancestors 'self' https://walkurls.com"
Header unset X-Frame-Options
Nginx
add_header Content-Security-Policy "frame-ancestors 'self' https://walkurls.com";
Node.js / Express
app.use((req, res, next) => {
  res.setHeader('Content-Security-Policy',
    "frame-ancestors 'self' https://walkurls.com");
  res.removeHeader('X-Frame-Options');
  next();
});
PHP
header("Content-Security-Policy: frame-ancestors 'self' https://walkurls.com");
header_remove("X-Frame-Options");
Vercel (vercel.json)
{
  "headers": [{
    "source": "/(.*)",
    "headers": [{
      "key": "Content-Security-Policy",
      "value": "frame-ancestors 'self' https://walkurls.com"
    }]
  }]
}
Netlify (_headers)
/*
  Content-Security-Policy: frame-ancestors 'self' https://walkurls.com
ᨈᨙᨔ

ᨅᨘᨀᨗ DevTools F12 → Console. ᨊᨑᨙᨀᨚ ᨑᨗᨅᨒᨚᨀᨗ:

Refused to display 'https://...' in a frame
because it set 'X-Frame-Options' to 'deny'.

ᨄᨑᨗᨀᨔ header ᨆᨙᨒᨕᨒᨘᨗ ᨈᨙᨑᨆᨗᨊᨒ:

curl -I https://your-site.com | grep -i "frame\|content-security"
ᨀᨕᨆᨊ
⚠ ᨕᨍ ᨄᨀᨙ frame-ancestors * ᨑᨗ ᨄᨑᨚᨉᨘᨀᨔᨗ

ᨔᨒᨒᨘ ᨈᨙᨊᨈᨘ: https://walkurls.com

ᨄᨗᨊᨈᨔ ᨀᨗᨅᨚᨑᨉ
ᨑᨗᨚᨒᨚ / ᨑᨗᨆᨘᨊᨑᨗ
Spaceᨁᨊᨗ ᨚᨈᨚ-ᨄᨘᨈᨑ
Home Endᨄᨗᨈᨆ / ᨄᨌᨄᨄᨙ
Sᨁᨊᨗ ᨔᨕᨗᨉᨅ
Fᨒᨕᨑ ᨄᨙᨊᨘ
?ᨄᨊᨙᨒ ᨅᨊᨘᨈ ᨙᨊᨙ