ʻAʻohe URL i hoʻouka ʻia
0 / 0

Hoʻopili i nā URL ma ka ʻaoʻao e hoʻomaka ai

Kaomi S e hoʻololi i ka ʻaoʻao  ·  ? no ke kōkua
Hiki i kēia pūnaewele ke pale i ka hoʻokomo iframe. Hiki ke ʻike hakahaka ka ʻaoʻao.

Kōkua a me ka Hoʻoponopono Pilikia
No ke aha ʻaʻole e hoʻouka kekahi pūnaewele
No ke aha ua hakahaka ka ʻaoʻao?

Nui nā pūnaewele e pale ana i ka hoʻokomo iframe ma o nā poʻo HTTP. He hiʻohiʻona palekana kēia e pale ana i ka clickjacking.

⚠ Pehea e hana ai ka pale

Hoʻouna nā pūnaewele i nā poʻo e haʻi ana i kāu polokalamu: "Mai hoʻokomo iaʻu." Hoʻolohe ka polokalamu → iframe hakahaka.

HeaderHopena
X-Frame-Options: DENYPale i nā mea a pau
X-Frame-Options: SAMEORIGINKa domain like wale nō
CSP: frame-ancestors 'none'Pale hou
Kūpono
PūnaeweleKūlana
Google, Gmail, GitHubPale ʻia
Facebook, X / TwitterPale ʻia
WikipediaHapa
Kāu mau pūnaewele ponoʻīHana ✓
Nā mea hana loko / papa kikohoʻeHana ✓
Pūnaewele paʻa / palapalaHana ✓
E hana i kāu mau pūnaewele
✓ Paipai ʻia

Hoʻonoho i ka frame-ancestors e ʻae wale i walkurls.com.

Apache (.htaccess)
Header set Content-Security-Policy "frame-ancestors 'self' https://walkurls.com"
Header unset X-Frame-Options
Nginx
add_header Content-Security-Policy "frame-ancestors 'self' https://walkurls.com";
Node.js / Express
app.use((req, res, next) => {
  res.setHeader('Content-Security-Policy',
    "frame-ancestors 'self' https://walkurls.com");
  res.removeHeader('X-Frame-Options');
  next();
});
PHP
header("Content-Security-Policy: frame-ancestors 'self' https://walkurls.com");
header_remove("X-Frame-Options");
Vercel (vercel.json)
{
  "headers": [{
    "source": "/(.*)",
    "headers": [{
      "key": "Content-Security-Policy",
      "value": "frame-ancestors 'self' https://walkurls.com"
    }]
  }]
}
Netlify (_headers)
/*
  Content-Security-Policy: frame-ancestors 'self' https://walkurls.com
Hoʻāʻo

Wehe i DevTools F12 → Console. Inā pale ʻia:

Refused to display 'https://...' in a frame
because it set 'X-Frame-Options' to 'deny'.

Nānā i nā poʻo ma ka terminal:

curl -I https://your-site.com | grep -i "frame\|content-security"
Palekana
⚠ Mai hoʻohana i frame-ancestors * i ka hana maoli

E kuhikuhi mau: https://walkurls.com

Nā ala pōkole papa pihi
Mua / Aʻe
SpaceHoʻololi pāʻani ʻakomi
Home EndMua loa / Hope loa
SHoʻololi ʻaoʻao
FPiha pale
?Kēia papa kōkua