Hmm, X-Frame-Options, huh? Guess I'll have to remember that one. Although, if someone's trying to Clickjack me, I'd just throw my computer out the window. Problem solved!
I thought the Access-Control-Allow-Origin header was for preventing cross-origin resource sharing attacks, not Clickjacking. Good thing I double-checked the options!
The X-Frame-Options header is definitely the correct answer here. Clickjacking is all about tricking users into clicking on something they didn't intend to, and this header helps prevent that by controlling whether a page can be embedded in an iframe.
Geoffrey
3 days agoFernanda
4 days agoHerminia
10 days agoNichelle
16 days agoAnisha
24 days agoMalissa
25 days ago