LoginSignup
11
12

More than 5 years have passed since last update.

[セキュリティ]クリックジャッキング

Posted at

クリックジャッキングとは

メモ

対策

X-Frame-Optionsを付与する

参考: https://developer.mozilla.org/ja/docs/The_X-Frame-Options_response_header

apache

Header always append X-Frame-Options SAMEORIGIN

nginx

add_header X-Frame-Options SAMEORIGIN;

ちなみに Railsだとこのへんっぽい
https://github.com/rails/rails/commit/bd59793043750c7c4545d14d618ce8ac40cc4d55

11
12
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
11
12