Nta URL yashyizwemo
0 / 0

Omeka URL mu ruhande kugira ngo utangire

Kanda S kugira ngo uhindure uruhande  ·  ? kugira ngo ubone ubufasha
Iyi mbuga nkoranyambaga ishobora guhagarika gushyirwa muri iframe. Ipaji ishobora kugaragara nta kintu kirimo.

Ubufasha n'Gukemura Ibibazo
Impamvu zimwe mu mbuga nkoranyambaga zidafunguka
Kuki ipaji iri ubusa?

Imbuga nkoranyambaga nyinshi zihagarika gushyirwa muri iframe binyuze mu ntumwa za HTTP. Iki ni ikintu cy'umutekano kirinda clickjacking.

⚠ Uko guhagarika bikora

Imbuga nkoranyambaga zohereza intumwa zibwira umushakisha wawe: "Ntumbishyire muri iframe." Umushakisha yumvira → iframe irimo ubusa.

IntumwaIngaruka
X-Frame-Options: DENYBihagarika byose
X-Frame-Options: SAMEORIGINDomaine imwe gusa
CSP: frame-ancestors 'none'Guhagarika kw'igihe gishya
Ubushobozi bwo Gukorana
UrubugaImiterere
Google, Gmail, GitHubByahagaritswe
Facebook, X / TwitterByahagaritswe
WikipediaIgice
Imbuga nkoranyambaga zawe bwiteBirakora ✓
Ibikoresho by'imbere / dashboardsBirakora ✓
Imbuga zihamye / inyandikoBirakora ✓
Kora ko imbuga zawe zikora
✓ Bisabwa

Shiraho frame-ancestors kugira ngo wemere walkurls.com gusa.

Apache (.htaccess)
Header set Content-Security-Policy "frame-ancestors 'self' https://walkurls.com"
Header unset X-Frame-Options
Nginx
add_header Content-Security-Policy "frame-ancestors 'self' https://walkurls.com";
Node.js / Express
app.use((req, res, next) => {
  res.setHeader('Content-Security-Policy',
    "frame-ancestors 'self' https://walkurls.com");
  res.removeHeader('X-Frame-Options');
  next();
});
PHP
header("Content-Security-Policy: frame-ancestors 'self' https://walkurls.com");
header_remove("X-Frame-Options");
Vercel (vercel.json)
{
  "headers": [{
    "source": "/(.*)",
    "headers": [{
      "key": "Content-Security-Policy",
      "value": "frame-ancestors 'self' https://walkurls.com"
    }]
  }]
}
Netlify (_headers)
/*
  Content-Security-Policy: frame-ancestors 'self' https://walkurls.com
Kugerageza

Fungura DevTools F12 → Console. Niba byahagaritswe:

Refused to display 'https://...' in a frame
because it set 'X-Frame-Options' to 'deny'.

Genzura intumwa binyuze muri terminal:

curl -I https://your-site.com | grep -i "frame\|content-security"
Umutekano
⚠ Ntukoreshe frame-ancestors * mu mushinga w'ikoreshwa

Buri gihe shyiraho: https://walkurls.com

Amayoborwa y'ibuto by'urwandiko
Iyibanziriza / Ikurikira
SpaceHindura gukina ku buryo bwikora
Home EndIya mbere / Iya nyuma
SHindura uruhande
FIkuzo yose
?Iki gice cy'ubufasha