3 ms·
You're right that everyone should be using X-Frame-Options: DENY (for ancient browsers, plus CSP for newer browsers), but the author managed to pull it off on G
by creata 10mo ago
You're right that everyone should be using X-Frame-Options: DENY (for ancient browsers, plus CSP for newer browsers), but the author managed to pull it off on Google Docs. If even Google can't consistently stick to it, I feel like I should be worried.
All website operators should read this imo: https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Headers_Cheat_Sheet.html https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Headers_...
- frigateengineer 10mo ago> If even Google can't consistently stick to it Everything is a target. You can’t assume safety based on reputation or ubiquitousness. There are so many examples of the trusted well-used thing failing security to mention.