Enable the X-Frame-Options header

We can configure the X-Frame-Options header settings to help you protect the site against Clickjacking. Clickjacking is a technique that tricks a web user into clicking a malicious site, thinking that it is the site. This malicious site can then reveal confidential information or take control of the user's computer.


About this task

We can help to protect the site from this form of attack by improving your X-Frame-Options header.

For more ways to protect the site from Clickjacking see, Clickjacking Defense Cheat Sheet. The following are possible values for our X-Frame-Options header:


Procedure

Include the X-Frame-Options header with a response.

The Aurora store has the X-Frame-Options header enabled using the HttpSecurityFilter. We can include this X-Frame-Options header using one of the following options: