-
Notifications
You must be signed in to change notification settings - Fork 53
TWA 0207
Thomas Young-Audet edited this page Jun 8, 2020
·
4 revisions
"X-Frame-Options is 'allow-from', consider 'deny' or 'none'"
The X-Frame-Options
header provide clickjacking protection to your site users by not allowing rendering of a page in a frame. The allow-from
directive allows the page to only be loaded in a frame on the specified origin and or domain. This is unsafe and can be abused.
In addition, if allow-from
is applied and the browser does not support it, then you have NO clickjacking defense in place.
The X-Frame-Options header is easy to change. It only requires a slight web server configuration modification. For more information about implementation visit MDN.