The X-Frame-Options HTTP header specifies whether your Drupal website can be displayed within other websites with the <frame>, <iframe>, <object>, or <embed> HTML tags. This improves Drupal security against clickjacking and related cyber attacks.
Below we’ll cover how to install the Security Kit module and enable X-Frames-Options.
Mozilla recommends using the superseding Content Security Policy frame-ancestors
attribute instead.
Install Security Kit
- Login to Drupal.
- Install the Drupal module using the Security Kit download link.
- Click Install at the bottom.
- Click Configuration at the top.
X-Frames-Options
- Under System, Click Security Kit settings.
- Under Clickjacking, click X-Frame-Options Header for options.
- Select an X-Frames-Options HTTP header:
SAMEORIGIN – your website can be framed in the same webpage (default option)
Disabled
DENY – website cannot be displayed in a frame
ALLOW-FROM – website can only be framed within URIs specified below; may not work in newer browsers. - At the bottom, click Save configuration.
Get high performance and security with our Managed Drupal Hosting.