add_header X-Frame-Options SAMEORIGIN;
时间: 2023-08-26 20:17:19 浏览: 160
X-Frame-Options头未设置 防止网页被iframe内框架调用
这行代码add_header X-Frame-Options SAMEORIGIN;是用于配置Nginx发送X-Frame-Options响应头的。它的作用是设置X-Frame-Options的值为SAMEORIGIN,从而限制页面的嵌套展示。通过这个配置,页面只能在相同的域名下被嵌套显示,不能跨域名嵌套。这样可以增加网站的安全性,防止点击劫持等攻击。<span class="em">1</span><span class="em">2</span><span class="em">3</span>
#### 引用[.reference_title]
- *1* [Web安全漏洞 之 X-Frame-Options响应头配置](https://blog.csdn.net/xp_lx1/article/details/80676630)[target="_blank" data-report-click={"spm":"1018.2226.3001.9630","extra":{"utm_source":"vip_chatgpt_common_search_pc_result","utm_medium":"distribute.pc_search_result.none-task-cask-2~all~insert_cask~default-1-null.142^v92^chatsearchT3_1"}}] [.reference_item style="max-width: 50%"]
- *2* *3* [360网站安全提示"X-Frame-Options头未设置"怎么解决](https://blog.csdn.net/qq_35624642/article/details/72976271)[target="_blank" data-report-click={"spm":"1018.2226.3001.9630","extra":{"utm_source":"vip_chatgpt_common_search_pc_result","utm_medium":"distribute.pc_search_result.none-task-cask-2~all~insert_cask~default-1-null.142^v92^chatsearchT3_1"}}] [.reference_item style="max-width: 50%"]
[ .reference_list ]
阅读全文