ojullien/Apache2.4

The 'X-Frame-Options' header should not be used

ojullien opened this issue · 0 comments

A similar effect, with more consistent support and stronger checks, can be achieved with the 'Content-Security-Policy' header and 'frame-ancestors' directive.