diff --git a/httpheader.php b/httpheader.php index 8d7d4e9..57859e0 100644 --- a/httpheader.php +++ b/httpheader.php @@ -328,7 +328,7 @@ private function setCspHeader() } // Add the xframeoptions directive to the CSP too when enabled - if ($this->params->get('xframeoptions')) + if ($this->params->get('xframeoptions', 1) || $this->params->get('frame_ancestors_self_enabled', 1)) { $newCspValues[] = "frame-ancestors 'self'"; } diff --git a/httpheader.xml b/httpheader.xml index 0f9d8c5..765c961 100644 --- a/httpheader.xml +++ b/httpheader.xml @@ -200,6 +200,18 @@ + + + +