Files
computer-playbook/roles/nginx-docker-reverse-proxy/templates/headers/iframe.conf.j2

5 lines
235 B
Django/Jinja

{% if applications.get(application_id, {}).get('features', {}).get('iframe', False) %}
add_header X-Frame-Options "SAMEORIGIN" always;
add_header Content-Security-Policy "frame-ancestors 'self' {{primary_domain}};" always;
{% endif %}