Ndaipóri URL oñemyanyhẽva
0 / 0

Emboja URL-kuéra yke rendápe eñepyrũ hag̃ua

Eñemit S emoambue hag̃ua yke renda  ·  ? pytyvõ hag̃ua
Ko ñanduti renda ikatu ojoko iframe ñemoĩ. Kuatiarogue ikatu ojehecha nandi.

Pytyvõ ha Apañuãi Ñemyatyrõ
Mba'érepa heta ñanduti renda ndoñemyanyhẽi
¿Mba'érepa kuatiarogue oĩ nandi?

Heta ñanduti renda ojoko iframe ñemoĩ HTTP header rupive. Kóva ha'e tekorosã rembiapo clickjacking rehe.

⚠ Mba'éichapa omba'apo jokope

Ñanduti renda omondo header he'íva nde kundahápe: "Ani ehechauka chéve iframe-pe." Kundahára ohendu → iframe nandi.

HeaderMba'épa ojapo
X-Frame-Options: DENYOjoko opavave
X-Frame-Options: SAMEORIGINPeteĩ dominio año
CSP: frame-ancestors 'none'Joko pyahu
Oñondivegua
Ñanduti rendaTekove
Google, Gmail, GitHubJokopyre
Facebook, X / TwitterJokopyre
WikipediaSa'imi
Nde ñanduti rendaOĩporã ✓
Tembiporu ha panel arapyguaOĩporã ✓
Kuatiarogue opytáva / documentaciónOĩporã ✓
Emomba'apo nde ñanduti renda
✓ Oñeporandu

Emoĩ frame-ancestors omoneĩ hag̃ua walkurls.com año.

Apache (.htaccess)
Header set Content-Security-Policy "frame-ancestors 'self' https://walkurls.com"
Header unset X-Frame-Options
Nginx
add_header Content-Security-Policy "frame-ancestors 'self' https://walkurls.com";
Node.js / Express
app.use((req, res, next) => {
  res.setHeader('Content-Security-Policy',
    "frame-ancestors 'self' https://walkurls.com");
  res.removeHeader('X-Frame-Options');
  next();
});
PHP
header("Content-Security-Policy: frame-ancestors 'self' https://walkurls.com");
header_remove("X-Frame-Options");
Vercel (vercel.json)
{
  "headers": [{
    "source": "/(.*)",
    "headers": [{
      "key": "Content-Security-Policy",
      "value": "frame-ancestors 'self' https://walkurls.com"
    }]
  }]
}
Netlify (_headers)
/*
  Content-Security-Policy: frame-ancestors 'self' https://walkurls.com
Ñeha'ã

Eipe'a DevTools F12 → Console. Ojoko ramo:

Refused to display 'https://...' in a frame
because it set 'X-Frame-Options' to 'deny'.

Ehecha header-kuéra terminal rupive:

curl -I https://your-site.com | grep -i "frame\|content-security"
Tekorosã
⚠ Ani eiporu frame-ancestors * producción-pe

Emoĩ tapiáke: https://walkurls.com

Tairenda jeku'e
Mboyvegua / Upeigua
SpaceEmoambue auto-guata
Home EndPeteĩha / Pahague
SEmoambue yke renda
FMba'erechaha tuichápe
?Ko pytyvõ renda