From 8d9bc10d8128aae03dfde62fd00075fe492ead10 Mon Sep 17 00:00:00 2001 From: Martin Pitt Date: Tue, 14 Sep 2021 09:02:33 +0200 Subject: [PATCH] common: Restrict frame embedding to same origin Declare `X-Frame-Options: sameorigin` [1] so that cockpit frames can only be embedded into pages coming from the same origin. This is similar to setting CORP in commit 2b38b8de92f9a (which applies to `