Forum Discussion
ASM-custom-response-page Enable X-Frame-Option
ASM Experts, Is there any potential impact when we enable X-Frame-option deny/Sameorgin on ASM Custom Violation response page? Please advice .Thanks
- Kash_276820
Nimbostratus
Experts Any updates?
- Jad_Tabbara__J1
Cirrostratus
Hello Kash,
If your "custom response page" contains and you add :</p> <ul> <li>"X-Frame-Options: DENY" then the browser will not load the iframe content </li> <li>"X-Frame-Options: SAMEORIGIN" then browser will load only iframe comming from same domain</li> </ul> <p>If your "custom response page" doesn't contain iframe there is no impact to do this on the blocking page itself. </p> <p>Regards</p>
- samstep
Cirrocumulus
Should be no impact - these headers provide Clickjacking attack mitigation
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com