Uploaded image for project: 'RH-SSO'
  1. RH-SSO
  2. RHSSO-841

Server Admin Guide: X-Frame-Options to "SAMEORIGIN https://www.google.com": Not a valid HTTP Header

XMLWordPrintable

      Clickjacking Section:

      Customer question via Customer Support:
      I believe there is an error in your documentation in this screenshot.

      (screenshot is attached)

      "You set the X-Frame-Options to "SAMEORIGIN https://www.google.com"

      This is not defined as being a valid HTTP Header, and therefore the browser will most likely ignore it.

      Could you please validate or not my question. If this setting is indeed valid, could you give me the necessary information which describes it as being a valid HTTP Header?"

        1. unknown.png
          317 kB
          Chuck Copello

            zschwarz Zuzana Schwarzová (Inactive)
            ccopello Chuck Copello
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: