Akukho URL elayishiweyo
0 / 0

Ncamathisela ii-URL kwibha esecaleni ukuze uqalise

Cinezela S ukutshintsha ibha esecaleni  ·  ? ukufumana uncedo
Le sayithi inokuthintela ukufakwa kwe-iframe. Iphepha linokubonakala lingenanto.

Uncedo nokuSombulula iiNgxaki
Kutheni ezinye iiwebhusayithi zingalayishi
Kutheni iphepha lingenanto?

Iiwebhusayithi ezininzi zithintela ukufakwa kwe-iframe ngezihloko ze-HTTP. Esi sisici sokhuseleko esikhuselayo kwi-clickjacking.

⚠ Ukuthintela kusebenza njani

Iiwebhusayithi zithumela izihloko zixelela ibhrawuza yakho: "Musa ukundifaka." Ibhrawuza iyathobela → i-iframe engenanto.

IsihlokoIsiphumo
X-Frame-Options: DENYIthintela konke
X-Frame-Options: SAMEORIGINIdomeyini efanayo kuphela
CSP: frame-ancestors 'none'Ukuthintela kwanamhlanje
Ukuhambelana
IsayithiImeko
Google, Gmail, GitHubIthintelwe
Facebook, X / TwitterIthintelwe
WikipediaInxalenye
Iiwebhusayithi zakhoIyasebenza ✓
Izixhobo zangaphakathi / iidashbhodiIyasebenza ✓
Iisayithi ezimileyo / amaxwebhuIyasebenza ✓
Yenza iisayithi zakho zisebenze
✓ Icetyiswayo

Cwangcisa frame-ancestors ukuvumela kuphela walkurls.com.

Apache (.htaccess)
Header set Content-Security-Policy "frame-ancestors 'self' https://walkurls.com"
Header unset X-Frame-Options
Nginx
add_header Content-Security-Policy "frame-ancestors 'self' https://walkurls.com";
Node.js / Express
app.use((req, res, next) => {
  res.setHeader('Content-Security-Policy',
    "frame-ancestors 'self' https://walkurls.com");
  res.removeHeader('X-Frame-Options');
  next();
});
PHP
header("Content-Security-Policy: frame-ancestors 'self' https://walkurls.com");
header_remove("X-Frame-Options");
Vercel (vercel.json)
{
  "headers": [{
    "source": "/(.*)",
    "headers": [{
      "key": "Content-Security-Policy",
      "value": "frame-ancestors 'self' https://walkurls.com"
    }]
  }]
}
Netlify (_headers)
/*
  Content-Security-Policy: frame-ancestors 'self' https://walkurls.com
Ukuvavanya

Vula i-DevTools F12 → Console. Ukuba ithintelwe:

Refused to display 'https://...' in a frame
because it set 'X-Frame-Options' to 'deny'.

Jonga izihloko ngetheminali:

curl -I https://your-site.com | grep -i "frame\|content-security"
Ukhuseleko
⚠ Musa ukusebenzisa frame-ancestors * kumveliso

Soloko ucacisa: https://walkurls.com

Izikroba zekhibhodi
Edlulileyo / Elandelayo
SpaceTshintsha ukudlala ngokuzenzekela
Home EndYokuqala / Yokugqibela
STshintsha ibha esecaleni
FIsikrini esipheleleyo
?Le phaneli yoncedo