diff --git a/.htaccess b/.htaccess index a824285..7eb6cc6 100644 --- a/.htaccess +++ b/.htaccess @@ -1,5 +1,5 @@ Header set Content-Security-Policy "default-src *; script-src 'self' ajax.googleapis.com; style-src 'self'" Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" -Header set X-Frame-Options "sameorigin" +# Header set X-Frame-Options "sameorigin" Header set X-XSS-Protection "1; mode=block" Header set X-Content-Type-Options "nosniff"