I'm wondering if we should also consider adding tools for the opposite side of mixed content, not allowing yourself to be embedded or framed by a non-secure site.
Something like X-Frame-Options: secure-only or perhaps a new CORP value? And perhaps advertising this through Fetch Metadata?
I'm wondering if we should also consider adding tools for the opposite side of mixed content, not allowing yourself to be embedded or framed by a non-secure site.
Something like
X-Frame-Options: secure-only
or perhaps a new CORP value? And perhaps advertising this through Fetch Metadata?