Leai se URL ua utaina
0 / 0

Fa'apipi'i URL i le pa'u i le itu e amata ai

Oomi le S e sui le pa'u i le itu  ·  ? mo fesoasoani
Atonu e polokaina e lenei saite le fa'aofiina o iframe. Atonu e foliga gaogao le itulau.

Fesoasoani & Fo'ia o Fa'afitauli
Aisea e le utaina ai nisi upega tafa'ilagi
Aisea e gaogao ai le itulau?

E tele upega tafa'ilagi e poloka le fa'aofiina o iframe e ala i HTTP headers. O se vaega puipuiga lea e puipuia ai mai le clickjacking.

⚠ Pe fa'apefea ona galue le polokaina

E auina atu e upega tafa'ilagi headers e ta'u atu i lau su'esu'ega: "Aua le fa'aofi a'u." E usiusita'i le su'esu'ega → iframe gaogao.

HeaderA'afiaga
X-Frame-Options: DENYPoloka uma
X-Frame-Options: SAMEORIGINItulagi tutusa lava
CSP: frame-ancestors 'none'Poloka faaonaponei
Fetaui
SaiteTulaga
Google, Gmail, GitHubPolokaina
Facebook, X / TwitterPolokaina
WikipediaVaega
Au lava upega tafa'ilagiGalue ✓
Meafaigaluega totonu / fa'aaligaGalue ✓
Saite tumau / pepaGalue ✓
Fa'agalue au saite
✓ Fautuaina

Seti le frame-ancestors e fa'atagaina na'o le walkurls.com.

Apache (.htaccess)
Header set Content-Security-Policy "frame-ancestors 'self' https://walkurls.com"
Header unset X-Frame-Options
Nginx
add_header Content-Security-Policy "frame-ancestors 'self' https://walkurls.com";
Node.js / Express
app.use((req, res, next) => {
  res.setHeader('Content-Security-Policy',
    "frame-ancestors 'self' https://walkurls.com");
  res.removeHeader('X-Frame-Options');
  next();
});
PHP
header("Content-Security-Policy: frame-ancestors 'self' https://walkurls.com");
header_remove("X-Frame-Options");
Vercel (vercel.json)
{
  "headers": [{
    "source": "/(.*)",
    "headers": [{
      "key": "Content-Security-Policy",
      "value": "frame-ancestors 'self' https://walkurls.com"
    }]
  }]
}
Netlify (_headers)
/*
  Content-Security-Policy: frame-ancestors 'self' https://walkurls.com
Su'ega

Tatala le DevTools F12 → Console. Afai e polokaina:

Refused to display 'https://...' in a frame
because it set 'X-Frame-Options' to 'deny'.

Siaki headers e ala i le terminal:

curl -I https://your-site.com | grep -i "frame\|content-security"
Puipuiga
⚠ Aua le fa'aogaina le frame-ancestors * i le galuega moni

Fa'ailoa pea: https://walkurls.com

Ki pu'upu'u
Talu ai / Sosoo
SpaceSui le ta'alo otometi
Home EndMuamua / Mulimuli
SSui le pa'u i le itu
FAta atoa
?Lenei laulau fesoasoani