Mana URL kargasqachu
0 / 0

URL-kunata kinray wachkupi k'askachiy qallarispa

S ñit'iy kinray wachku t'ikraypaq  ·  ? yanapay kichaypaq
Kay web kitiqa iframe sat'iyta hark'anmanmi. P'anqaqa ch'usaq rikurinmanmi.

Yanapay & Sasachakuy Allichay
Imanaqtinmi wakin web kitikuna mana kargakunkuchu
¿Imanaqtinmi p'anqaqa ch'usaq?

Achka web kitikuna iframe sat'iyta hark'anku HTTP uma qillqakunawan. Kayqa waqaychay ruwaymi clickjacking-manta jark'aq.

⚠ Imaynan hark'ayqa llamk'an

Web kitikuna uma qillqakunata apachinku ñit'iqniykiman: "Ama sat'iwaychu." Ñit'iqqa kasun → ch'usaq iframe.

Uma qillqaRuway
X-Frame-Options: DENYTukuyta hark'an
X-Frame-Options: SAMEORIGINKikin kiti sapalla
CSP: frame-ancestors 'none'Kunan pacha hark'ay
Tupanakuy
Web kitiImaynakaynin
Google, Gmail, GitHubHark'asqa
Facebook, X / TwitterHark'asqa
WikipediaWakinlla
Qampa web kitiykikunaLlamk'an ✓
Ukhu llamk'ana / tablero-kunaLlamk'an ✓
Mana kuyuq kiti / qillqa-kunaLlamk'an ✓
Web kitiykikunata llamk'achiy
✓ Allin yuyaychay

frame-ancestors nisqata churay walkurls.com sapallanpaq.

Apache (.htaccess)
Header set Content-Security-Policy "frame-ancestors 'self' https://walkurls.com"
Header unset X-Frame-Options
Nginx
add_header Content-Security-Policy "frame-ancestors 'self' https://walkurls.com";
Node.js / Express
app.use((req, res, next) => {
  res.setHeader('Content-Security-Policy',
    "frame-ancestors 'self' https://walkurls.com");
  res.removeHeader('X-Frame-Options');
  next();
});
PHP
header("Content-Security-Policy: frame-ancestors 'self' https://walkurls.com");
header_remove("X-Frame-Options");
Vercel (vercel.json)
{
  "headers": [{
    "source": "/(.*)",
    "headers": [{
      "key": "Content-Security-Policy",
      "value": "frame-ancestors 'self' https://walkurls.com"
    }]
  }]
}
Netlify (_headers)
/*
  Content-Security-Policy: frame-ancestors 'self' https://walkurls.com
Llank'aychay

DevTools kichay F12 → Console. Hark'asqa kaptinqa:

Refused to display 'https://...' in a frame
because it set 'X-Frame-Options' to 'deny'.

Uma qillqakunata terminal-wan qhaway:

curl -I https://your-site.com | grep -i "frame\|content-security"
Waqaychay
⚠ Ama hayk'aqpas frame-ancestors * nisqata producción-pi llamk'achiychu

Hayk'aqpas sutichay: https://walkurls.com

Tiklakuna ñit'iykuna
Ñawpaq / Qhipa
SpaceKikinmanta purichiy t'ikray
Home EndÑawpaq kaq / Qhipa kaq
SKinray wachku t'ikray
FHunt'a qhawana
?Kay yanapay t'aqa