Closed daniel-ac-martin closed 3 months ago
![]() |
![]() |
![]() |
![]() |
![]() |
Details:
plop-pack: Take advantage of frameAncestors option | |||
Project: NotGovUK | Commit: 1781906aef |
||
Status: Passed | Duration: 12:08 💡 | ||
Started: Apr 3, 2024 4:21 PM | Ended: Apr 3, 2024 4:34 PM |
Allows the user to provide a
frameAncestors
option to the engine, which follows the Content Security Policy format. An equivalent environment variable has also been created.Examples
Only allow us to put our pages in frames:
Note: Pay attention to the single quotes!
Also allow example.com and its subdomains:
Allow all frames (not advised):
To disallow frames (default):
We disallow frames by default in order to prevent click jacking.
Partially addresses: #950