Ha ho URL e laetsweng
0 / 0

Kenya di-URL ka baraneng e ka thoko ho qala

Tobetsa S ho fetola bara e ka thoko  ·  ? bakeng sa thuso
Wepesaete ena e ka thibela ho kenyeletswa ha iframe. Leqephe le ka hlaha le le feela.

Thuso le Tharollo ya Mathata
Hobaneng diwepesaete tse ding di sa loutehe
Hobaneng leqephe le le feela?

Diwepesaete tse ngata di thibela ho kenyeletswa ha iframe ka di-header tsa HTTP. Sena ke tshireletso e thibelang clickjacking.

⚠ Thibelo e sebetsa jwang

Diwepesaete di romela di-header tse bolellang sebatli sa hao: "O se ke wa nkenyeletsa." Sebatli se mamela → iframe e feela.

HeaderSephetho
X-Frame-Options: DENYE thibela tsohle
X-Frame-Options: SAMEORIGINDomain e tshwanang feela
CSP: frame-ancestors 'none'Thibelo ya sejoale-joale
Ho Tshwaneleha
WepesaeteBoemo
Google, Gmail, GitHubE thibilwe
Facebook, X / TwitterE thibilwe
WikipediaKa karolo
Diwepesaete tsa haoE sebetsa ✓
Dithulusi tsa kahare / di-dashboardE sebetsa ✓
Diwepesaete tse tsitsitseng / ditokomaneE sebetsa ✓
Etsa hore diwepesaete tsa hao di sebetse
✓ E kgothalletswang

Beha frame-ancestors ho dumella walkurls.com feela.

Apache (.htaccess)
Header set Content-Security-Policy "frame-ancestors 'self' https://walkurls.com"
Header unset X-Frame-Options
Nginx
add_header Content-Security-Policy "frame-ancestors 'self' https://walkurls.com";
Node.js / Express
app.use((req, res, next) => {
  res.setHeader('Content-Security-Policy',
    "frame-ancestors 'self' https://walkurls.com");
  res.removeHeader('X-Frame-Options');
  next();
});
PHP
header("Content-Security-Policy: frame-ancestors 'self' https://walkurls.com");
header_remove("X-Frame-Options");
Vercel (vercel.json)
{
  "headers": [{
    "source": "/(.*)",
    "headers": [{
      "key": "Content-Security-Policy",
      "value": "frame-ancestors 'self' https://walkurls.com"
    }]
  }]
}
Netlify (_headers)
/*
  Content-Security-Policy: frame-ancestors 'self' https://walkurls.com
Ho Leka

Bula DevTools F12 → Console. Haeba e thibilwe:

Refused to display 'https://...' in a frame
because it set 'X-Frame-Options' to 'deny'.

Hlahloba di-header ka terminal:

curl -I https://your-site.com | grep -i "frame\|content-security"
Tshireletso
⚠ O se ke wa sebedisa frame-ancestors * tlhahisong

Kamehla hlalosa: https://walkurls.com

Dikgutshutso tsa kibotho
E fetileng / E latelang
SpaceFetola ho bapala ka bo eona
Home EndYa pele / Ya ho qetela
SFetola bara e ka thoko
FSkrini e tletseng
?Panele ena ya thuso