Skip to content

Commit acacc34

Browse files
committed
restrict iframe usage to mitigate clickjacking
1 parent 474447a commit acacc34

File tree

2 files changed

+10
-1
lines changed

2 files changed

+10
-1
lines changed

package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "orcfax.io",
3-
"version": "2025-05-20",
3+
"version": "2025-07-21",
44
"private": true,
55
"scripts": {
66
"dev": "vite dev",

src/hooks.server.ts

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
import type { Handle } from "@sveltejs/kit";
2+
3+
export const handle: Handle = async ({ event, resolve }) => {
4+
const response = await resolve(event);
5+
response.headers.set("X-Frame-Options", "SAMEORIGIN");
6+
response.headers.set("Content-Security-Policy", "frame-ancestors 'none'");
7+
8+
return response;
9+
};

0 commit comments

Comments
 (0)