diff --git a/services/nginx/default.nix b/services/nginx/default.nix index 498c894..d6b3bc6 100644 --- a/services/nginx/default.nix +++ b/services/nginx/default.nix @@ -63,7 +63,7 @@ in add_header 'Referrer-Policy' 'origin-when-cross-origin'; # Disable embedding as a frame - add_header X-Frame-Options DENY; + add_header X-Frame-Options SAMEORIGIN; # Prevent injection of code in other mime types (XSS Attacks) add_header X-Content-Type-Options nosniff;