Skip to content

Prevent nesting site in iFrame#2148

Merged
scottmakestech merged 1 commit intomainfrom
issue-1080-prevent-nesting-in-iframe
Feb 13, 2026
Merged

Prevent nesting site in iFrame#2148
scottmakestech merged 1 commit intomainfrom
issue-1080-prevent-nesting-in-iframe

Conversation

@scottmakestech
Copy link
Collaborator

@scottmakestech scottmakestech commented Feb 13, 2026

Sets frame-ancestors property to none to prevent nesting this site in an iframe. Although we already set X-Frame-Options to deny, this is the modern CSP method for declaring this setting. Fixes #1080.

scottmakestech added a commit to abetterinternet/website that referenced this pull request Feb 13, 2026
Sets frame-ancestors property to none to prevent nesting this site in an iframe. Although we already set X-Frame-Options to deny, this is the modern CSP method for declaring this setting. Sees letsencrypt/website#1080 and letsencrypt/website#2148.
scottmakestech added a commit to divviup/website that referenced this pull request Feb 13, 2026
Adds X-Frame-Options and CSP frame-ancestors headers to prevent this site from being embedded in an iframe on other domains. X-Frame-Options is the legacy header; frame-ancestors is the modern CSP equivalent. Both are set for maximum browser compatibility. See letsencrypt/website#1080 and letsencrypt/website#2148.
scottmakestech added a commit to memorysafety/website that referenced this pull request Feb 13, 2026
Adds X-Frame-Options and CSP frame-ancestors headers to prevent this site from being embedded in an iframe on other domains. X-Frame-Options is the legacy header; frame-ancestors is the modern CSP equivalent. Both are set for maximum browser compatibility. See letsencrypt/website#1080 and letsencrypt/website#2148.
scottmakestech added a commit to abetterinternet/website that referenced this pull request Feb 13, 2026
Sets frame-ancestors property to none to prevent nesting this site in an iframe. Although we already set X-Frame-Options to deny, this is the modern CSP method for declaring this setting. Sees letsencrypt/website#1080 and letsencrypt/website#2148.
scottmakestech added a commit to divviup/website that referenced this pull request Feb 13, 2026
Adds X-Frame-Options and CSP frame-ancestors headers to prevent this site from being embedded in an iframe on other domains. X-Frame-Options is the legacy header; frame-ancestors is the modern CSP equivalent. Both are set for maximum browser compatibility. See letsencrypt/website#1080 and letsencrypt/website#2148.
@scottmakestech
Copy link
Collaborator Author

Closes #1080, prevents nesting the website within an iframe. While this setting already existed, this is an updated version of the CSP syntax for modern browser compatiblity. I've applied this change to all 4 of ISRG's currently active websites - see this PR on github to see linked PRs for those repos. CC @bdaehlie

@scottmakestech scottmakestech merged commit d6d78f6 into main Feb 13, 2026
5 checks passed
@scottmakestech scottmakestech deleted the issue-1080-prevent-nesting-in-iframe branch February 13, 2026 21:30
scottmakestech added a commit to memorysafety/website that referenced this pull request Feb 13, 2026
Adds X-Frame-Options and CSP frame-ancestors headers to prevent this site from being embedded in an iframe on other domains. X-Frame-Options is the legacy header; frame-ancestors is the modern CSP equivalent. Both are set for maximum browser compatibility. See letsencrypt/website#1080 and letsencrypt/website#2148.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant