Quantcast
Channel: Active questions tagged header - Stack Overflow
Viewing all articles
Browse latest Browse all 649

Are Header always set X-Frame-Options "SAMEORIGIN" and Header set Content-Security-Policy: "frame-ancestors 'none'" duplicates or are both useful?

$
0
0

Sorry to trouble and please forgive if duplicate but I have looked!

I am trying to assemble security headers for htaccess to help my customers pass PCI Compliance.

I am not at all sure whether...

Header always set X-Frame-Options "SAMEORIGIN"

Header set Content-Security-Policy: "frame-ancestors 'none'"

...are essentially duplicates or whether they each have a role to play?

Advice gratefully received - thank you!


Viewing all articles
Browse latest Browse all 649

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>