Remove invalid X-Frame-Options: ALLOWALL (#25070)

th-downstream
Claire 1 year ago committed by GitHub
parent 29ca815465
commit 0b4d3bf363

@ -45,6 +45,6 @@ class MediaController < ApplicationController
end end
def allow_iframing def allow_iframing
response.headers['X-Frame-Options'] = 'ALLOWALL' response.headers.delete('X-Frame-Options')
end end
end end

@ -45,7 +45,7 @@ class StatusesController < ApplicationController
return not_found if @status.hidden? || @status.reblog? return not_found if @status.hidden? || @status.reblog?
expires_in 180, public: true expires_in 180, public: true
response.headers['X-Frame-Options'] = 'ALLOWALL' response.headers.delete('X-Frame-Options')
render layout: 'embedded' render layout: 'embedded'
end end

Loading…
Cancel
Save