diff --git a/roles/pagure/frontend/templates/securityheaders.conf b/roles/pagure/frontend/templates/securityheaders.conf index 6712d74881..39b1b32a40 100644 --- a/roles/pagure/frontend/templates/securityheaders.conf +++ b/roles/pagure/frontend/templates/securityheaders.conf @@ -1,4 +1,4 @@ -Header always set X-Frame-Options "DENY" +Header always set X-Frame-Options "SAMEORIGIN" Header always set X-Xss-Protection "1; mode=block" Header always set X-Content-Type-Options "nosniff" Header always set Referrer-Policy "same-origin"