Skip to content

Commit 99e57ff

Browse files
committed
fix: relax csp iframe restriction (2)
1 parent e0a3ccd commit 99e57ff

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

src/hooks.server.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ const headersHandler = (async ({ event, resolve }) => {
1111
response.headers.set("Permissions-Policy", "accelerometer=(), autoplay=(), camera=(), encrypted-media=(), fullscreen=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), sync-xhr=(), usb=(), xr-spatial-tracking=(), geolocation=()");
1212
response.headers.set("X-Content-Type-Options", "nosniff");
1313
response.headers.set("Strict-Transport-Security", "max-age=31536000; includeSubDomains; preload");
14-
response.headers.set("X-Frame-Options", "DENY");
14+
// response.headers.set("X-Frame-Options", "DENY");
1515

1616
// Cross-Origin policies
1717
// COEP intentionally unsafe-none: tightening would require all cross-origin

0 commit comments

Comments
 (0)