Tsis muaj URL thauj
0 / 0

Muab URLs tso rau hauv sidebar kom pib

Nias S hloov sidebar  ·  ? rau kev pab
Lub website no yuav thaiv kev siv iframe. Nplooj ntawv yuav tshwm khoob.

Kev Pab & Kev Daws Teeb Meem
Vim li cas ib txhia websites tsis thauj
Vim li cas nplooj ntawv khoob?

Ntau lub websites thaiv kev siv iframe los ntawm HTTP headers. Qhov no yog ib qho kev ruaj ntseg tiv thaiv clickjacking.

⚠ Kev thaiv ua haujlwm li cas

Cov websites xa cov headers qhia koj lub browser: "Txhob embed kuv." Lub browser mloog → iframe khoob.

HeaderKev Cuam Tshuam
X-Frame-Options: DENYThaiv tag nrho
X-Frame-Options: SAMEORIGINTib lub domain nkaus xwb
CSP: frame-ancestors 'none'Kev thaiv tshiab
Kev Sib Haum
WebsiteXwm Txheej
Google, Gmail, GitHubRaug Thaiv
Facebook, X / TwitterRaug Thaiv
WikipediaIb Nrab
Koj cov websitesUa Haujlwm ✓
Cov cuab yeej sab hauv / dashboardsUa Haujlwm ✓
Cov sites zoo li qub / ntawvUa Haujlwm ✓
Ua kom koj cov sites ua haujlwm
✓ Pom Zoo

Teeb frame-ancestors kom tso cai rau walkurls.com nkaus xwb.

Apache (.htaccess)
Header set Content-Security-Policy "frame-ancestors 'self' https://walkurls.com"
Header unset X-Frame-Options
Nginx
add_header Content-Security-Policy "frame-ancestors 'self' https://walkurls.com";
Node.js / Express
app.use((req, res, next) => {
  res.setHeader('Content-Security-Policy',
    "frame-ancestors 'self' https://walkurls.com");
  res.removeHeader('X-Frame-Options');
  next();
});
PHP
header("Content-Security-Policy: frame-ancestors 'self' https://walkurls.com");
header_remove("X-Frame-Options");
Vercel (vercel.json)
{
  "headers": [{
    "source": "/(.*)",
    "headers": [{
      "key": "Content-Security-Policy",
      "value": "frame-ancestors 'self' https://walkurls.com"
    }]
  }]
}
Netlify (_headers)
/*
  Content-Security-Policy: frame-ancestors 'self' https://walkurls.com
Kev Sim

Qhib DevTools F12 → Console. Yog raug thaiv:

Refused to display 'https://...' in a frame
because it set 'X-Frame-Options' to 'deny'.

Tshuaj xyuas cov headers hauv terminal:

curl -I https://your-site.com | grep -i "frame\|content-security"
Kev Ruaj Ntseg
⚠ Tsis txhob siv frame-ancestors * hauv kev tsim khoom

Ib txwm qhia meej: https://walkurls.com

Kev luv keyboard
Rov Qab / Tom Ntej
SpaceHloov auto-play
Home EndThawj / Kawg
SHloov sidebar
FPuv screen
?Daim phiaj kev pab no