浏览代码

Disable iframing of the main domain using meta tags as well

Nariman Jelveh 1 年之前
父节点
当前提交
3cba4cab1e
共有 1 个文件被更改,包括 3 次插入0 次删除
  1. 3 0
      packages/backend/src/temp/puter_page_loader.js

+ 3 - 0
packages/backend/src/temp/puter_page_loader.js

@@ -75,6 +75,9 @@ const generate_puter_page_html = ({
     <meta property="og:description" content="${e((short_description).replace(/\n/g, " "))}">
     <meta property="og:image" content="${asset_dir}/images/screenshot.png">
 
+    <!-- disable iframes -->
+    <meta http-equiv="X-Frame-Options" content="sameorigin">
+
     <!-- Twitter meta tags -->
     <meta name="twitter:card" content="summary_large_image">
     <meta property="twitter:domain" content="puter.com">