Ahmo tlatēmōlli URL
0 / 0

Xiquintzaloa URLs ipan tēntli ic tīpēhuaz

Xictēqui S ic ticpatlā tēntli  ·  ? ic palēhuiliztli
Inīn āmatl web huelīz quitzacuīlīz iframe tlamantli. In āmatl huelīz iztāc nēziz.

Palēhuiliztli īhuān Tlahtlaniliztli
Tlēīca cequi āmatlahcuilōlmeh web ahmo tlatēmoa
¿Tlēīca in āmatl iztāc?

Mīec āmatlahcuilōlmeh web quitzacuīliah iframe tlamantli īca HTTP tzontecomeh. Inīn cē tlapiyaliztli ic ahmo clickjacking.

⚠ Quēnin tēquitia in tzacualiztli

Āmatlahcuilōlmeh web quintitlaniah tzontecomeh quitēilhuiah monavegador: "Ahmo xinēchtlāli." In navegador quitlacamati → iztāc iframe.

TzontecomatlTlamantli
X-Frame-Options: DENYQuitzacuīlia mochi
X-Frame-Options: SAMEORIGINZan cē dominio
CSP: frame-ancestors 'none'Yancuīc tzacualiztli
Tlanāmiquiliztli
Āmatl WebTlamantli
Google, Gmail, GitHubTzacuhtoc
Facebook, X / TwitterTzacuhtoc
WikipediaAhmo mochi
Moāmatlahcuilōlhuān webTēquitia ✓
Calītic tēquitilōni / tablerosTēquitia ✓
Āmatl web ahmo molīnia / documentosTēquitia ✓
Xicchīhua ma tēquitican moāmatlahcuilōlhuān
✓ Tlahtōlnāhuatīlli

Xictlāli frame-ancestors ic zan quicāhuaz walkurls.com.

Apache (.htaccess)
Header set Content-Security-Policy "frame-ancestors 'self' https://walkurls.com"
Header unset X-Frame-Options
Nginx
add_header Content-Security-Policy "frame-ancestors 'self' https://walkurls.com";
Node.js / Express
app.use((req, res, next) => {
  res.setHeader('Content-Security-Policy',
    "frame-ancestors 'self' https://walkurls.com");
  res.removeHeader('X-Frame-Options');
  next();
});
PHP
header("Content-Security-Policy: frame-ancestors 'self' https://walkurls.com");
header_remove("X-Frame-Options");
Vercel (vercel.json)
{
  "headers": [{
    "source": "/(.*)",
    "headers": [{
      "key": "Content-Security-Policy",
      "value": "frame-ancestors 'self' https://walkurls.com"
    }]
  }]
}
Netlify (_headers)
/*
  Content-Security-Policy: frame-ancestors 'self' https://walkurls.com
Tlayeyecōliztli

Xictlapō DevTools F12 → Console. Intlā tzacuhtoc:

Refused to display 'https://...' in a frame
because it set 'X-Frame-Options' to 'deny'.

Xictlachia tzontecomeh īca terminal:

curl -I https://your-site.com | grep -i "frame\|content-security"
Tlapiyaliztli
⚠ Ahmo quēmman xictēqui frame-ancestors * ipan tēquitiliztli

Nochipa xicnēxtī: https://walkurls.com

Tēpōztlahtōlāmatl ōhtlatzimmeh
Achtopa / Niman
SpaceXicpatlā auto-nēnēmiliztli
Home EndĀchto / Tlamian
SXicpatlā tēntli
FMochi pantalla
?Inīn palēhuiliztli āmatl