Documentation on X-FRAME-OPTIONS (to prevent clickjacking in IE8)


  • I haven't seen recent new content published about this.

    Does anybody have a link to the docs on it.

    I assume you can put:

    <meta http-equiv="X-FRAME-OPTIONS" content="DENY" />
    <meta http-equiv="X-FRAME-OPTIONS" content="SAMEORIGIN" />

    In your head, but I'd prefer to see it officially written up.

    • Edited by MikeGale Saturday, July 04, 2009 9:54 PM Improve
    Saturday, July 04, 2009 9:54 PM