3 ms·
Some of the new HTTP headers are just a mess. Did you know that X-Frame-Options' Allow-From option only allows you to whitelist one URL? Not a domain - a URL. T
by bluetooth 14y ago
Some of the new HTTP headers are just a mess. Did you know that X-Frame-Options' Allow-From option only allows you to whitelist one URL? Not a domain - a URL. The RFC actually expects you to communicate via another channel to determine whether or not a URL will be allowed to frame your page.
Luckily, this one is still a draft...
- homakov 14y agoyes lol. design pisses me off. Why didn't they put XFO into Content security policy yet!
- Dylan16807 14y agoWell if you assume that referer is turned on...