xwp 11 页面允许被frame嵌套 - nuanxin1111/react GitHub Wiki

nginx设置

使用 X-Frame-Options 有三个可选的值:

  • DENY:浏览器拒绝当前页面加载任何Frame页面
  • SAMEORIGIN:frame页面的地址只能为同源域名下的页面
  • ALLOW-FROM:url为允许frame加载的页面地址

django设置

in my Django settings.py file I have

MIDDLEWARE_CLASSES = (
  ....
  'django.middleware.clickjacking.XFrameOptionsMiddleware',
)

and

X_FRAME_OPTIONS = 'ALLOW-FROM http://123.123.123.123/'

参考:

http://stackoverflow.com/questions/22044725/how-to-allow-x-frame-options-for-facebook-in-django-app