Fix PDF export: allow same-origin iframes (X-Frame-Options)

This commit is contained in:
Maurice
2026-03-19 14:44:35 +01:00
parent 173d6cd953
commit 4d9854062c

View File

@@ -47,7 +47,7 @@ app.use(express.json());
// Security headers
app.use((req, res, next) => {
res.setHeader('X-Content-Type-Options', 'nosniff');
res.setHeader('X-Frame-Options', 'DENY');
res.setHeader('X-Frame-Options', 'SAMEORIGIN');
res.setHeader('X-XSS-Protection', '1; mode=block');
res.setHeader('Referrer-Policy', 'strict-origin-when-cross-origin');
next();