Uploaded image for project: 'RH-SSO'
  1. RH-SSO
  2. RHSSO-841

Server Admin Guide: X-Frame-Options to "SAMEORIGIN https://www.google.com": Not a valid HTTP Header

XMLWordPrintable

      Clickjacking Section:

      Customer question via Customer Support:
      I believe there is an error in your documentation in this screenshot.

      (screenshot is attached)

      "You set the X-Frame-Options to "SAMEORIGIN https://www.google.com"

      This is not defined as being a valid HTTP Header, and therefore the browser will most likely ignore it.

      Could you please validate or not my question. If this setting is indeed valid, could you give me the necessary information which describes it as being a valid HTTP Header?"

        1. unknown.png
          317 kB
          Chuck Copello

              zschwarz Zuzana Schwarzová (Inactive)
              ccopello Chuck Copello
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: