From 0ed328280ef1596484ce85fd1cdbdb39a174e613 Mon Sep 17 00:00:00 2001 From: Tommy Date: Wed, 12 Apr 2023 07:58:38 -0400 Subject: [PATCH] Change X-Frame-Options to SAMEORIGIN Signed-off-by: Tommy --- swag/nginx/ssl.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/swag/nginx/ssl.conf b/swag/nginx/ssl.conf index 2c1be2e..91a6218 100644 --- a/swag/nginx/ssl.conf +++ b/swag/nginx/ssl.conf @@ -33,7 +33,7 @@ add_header Permissions-Policy "accelerometer=(), ambient-light-sensor=(), autopl add_header Referrer-Policy "same-origin" always; add_header X-Content-Type-Options "nosniff" always; #add_header X-UA-Compatible "IE=Edge" always; -add_header X-Frame-Options "DENY" always; +add_header X-Frame-Options "SAMEORIGIN" always; add_header X-XSS-Protection "0" always; add_header Cross-Origin-Resource-Policy cross-origin; add_header Cross-Origin-Opener-Policy same-origin;