Skip to content

Comments

Prevent nesting site in iFrame#252

Merged
scottmakestech merged 1 commit intomainfrom
prevent-nesting-in-iframe
Feb 13, 2026
Merged

Prevent nesting site in iFrame#252
scottmakestech merged 1 commit intomainfrom
prevent-nesting-in-iframe

Conversation

@scottmakestech
Copy link
Collaborator

Adds X-Frame-Options (legacy header) and CSP frame-ancestors (modern CSP equivalent) headers to prevent this site from being embedded in an iframe on other domains. See letsencrypt/website#1080 and letsencrypt/website#2148.

Sets frame-ancestors property to none to prevent nesting this site in an iframe. Although we already set X-Frame-Options to deny, this is the modern CSP method for declaring this setting. Sees letsencrypt/website#1080 and letsencrypt/website#2148.
@scottmakestech scottmakestech merged commit 649a639 into main Feb 13, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant