Enweghị URL ebutere
0 / 0

Tinye URL na sidebar iji malite

Pịa S iji gbanwee sidebar  ·  ? maka enyemaka
Webụsaịtị a nwere ike igbochi itinye iframe. Peeji ahụ nwere ike ịpụta ihe efu.

Enyemaka & Idozi Nsogbu
Ihe mere ụfọdụ webụsaịtị na-adịghị ebu
Gịnị mere peeji ahụ ji bụrụ ihe efu?

Ọtụtụ webụsaịtị na-egbochi itinye iframe site na nkụnye isi HTTP. Nke a bụ njirimara nchekwa na-echekwa megide clickjacking.

⚠ Otu igbochi si arụ ọrụ

Webụsaịtị na-eziga nkụnye isi na-agwa ihe nchọgharị gị: "Etinyela m." Ihe nchọgharị ahụ na-erubere isi → iframe efu.

Nkụnye isiMmetụta
X-Frame-Options: DENYNa-egbochi ihe niile
X-Frame-Options: SAMEORIGINOtu domain naanị
CSP: frame-ancestors 'none'Igbochi ọgbara ọhụrụ
Ndakọrịta
SaịtịỌnọdụ
Google, Gmail, GitHubEgbochiri
Facebook, X / TwitterEgbochiri
WikipediaAkụkụ ụfọdụ
Webụsaịtị nke gịNa-arụ ọrụ ✓
Ngwaọrụ ime / dashboardsNa-arụ ọrụ ✓
Saịtị kwụ ọtọ / akwụkwọNa-arụ ọrụ ✓
Mee ka saịtị gị rụọ ọrụ
✓ A na-akwado

Tọọ frame-ancestors ka ọ kwere naanị walkurls.com.

Apache (.htaccess)
Header set Content-Security-Policy "frame-ancestors 'self' https://walkurls.com"
Header unset X-Frame-Options
Nginx
add_header Content-Security-Policy "frame-ancestors 'self' https://walkurls.com";
Node.js / Express
app.use((req, res, next) => {
  res.setHeader('Content-Security-Policy',
    "frame-ancestors 'self' https://walkurls.com");
  res.removeHeader('X-Frame-Options');
  next();
});
PHP
header("Content-Security-Policy: frame-ancestors 'self' https://walkurls.com");
header_remove("X-Frame-Options");
Vercel (vercel.json)
{
  "headers": [{
    "source": "/(.*)",
    "headers": [{
      "key": "Content-Security-Policy",
      "value": "frame-ancestors 'self' https://walkurls.com"
    }]
  }]
}
Netlify (_headers)
/*
  Content-Security-Policy: frame-ancestors 'self' https://walkurls.com
Ule

Mepee DevTools F12 → Console. Ọ bụrụ na egbochiri:

Refused to display 'https://...' in a frame
because it set 'X-Frame-Options' to 'deny'.

Lelee nkụnye isi site na terminal:

curl -I https://your-site.com | grep -i "frame\|content-security"
Nchekwa
⚠ Ejila frame-ancestors * na mmepụta

Na-ekwupụta mgbe niile: https://walkurls.com

Ụzọ mkpirisi igodo
Nke Gara Aga / Nke Ọzọ
SpaceGbanwee igwu akpaaka
Home EndNke Mbụ / Nke Ikpeazụ
SGbanwee sidebar
FIhuenyo zuru oke
?Panel enyemaka a