• Resolved timholz

    (@timholz)


    Hi – File Security > Frames >  «Enable this to stop other sites from displaying your content in a frame or iframe.» X-Frame-Options are a part of content-security-header (frame-ancestors). And your plugin is not really adding the X-Frame-Options Header but rather a Content-Security-Policy-Header.

    This is a bit confusing and in my case enabling this option overrides my own csp-rules sent with wordpress send_headers function. I disabled the option for my own csp takes care of that. It would be helpful, if this option was described more clearly.

    regards theo

    • This topic was modified 5 months, 3 weeks ago by timholz.
Viewing 4 replies - 1 through 4 (of 4 total)
Viewing 4 replies - 1 through 4 (of 4 total)

You must be logged in to reply to this topic.