The x-frame-options response header has 3 values:
DENY: Indicates that the page is not allowed to be displayed in a frame, even if it is nested in a page of the same domain name.
Sameorigin: Indicates that the page can be displayed in a frame on the same domain Name page.
Allow-from URI: Indicates that the page can be displayed in a frame of the specified source.
nginx Configuration : Add the following line to the nginx.conf "http" or "Server" or "location"
add_header X-Frame-Options
Sameorigin;
IIS configuration: Add the following line to the Web. config
<system.webServer>
...
<customHeaders>
<add name= "x-frame-options" value= "Sameorigin"/>
</customHeaders>
...
</system.webServer>
Apache configuration : Add the following line to the site
Header always append x-frame-options sameorigin
The x-frame-options in the HTTP response header prevents the Frame from being