We're calling on all EU-based Mozillians with iOS or iPadOS devices to help us monitor Apple’s new browser choice screens. Join the effort to hold Big Tech to account!

Kërkoni te Asistenca

Shmangni karremëzime gjoja asistence. S’do t’ju kërkojmë kurrë të bëni një thirrje apo të dërgoni tekst te një numër telefoni, apo të na jepni të dhëna personale. Ju lutemi, raportoni veprimtari të dyshimtë duke përdorur mundësinë “Raportoni Abuzim”.

Mësoni Më Tepër

How to detect x-frame-options when loading a website in iframe

  • 2 përgjigje
  • 1 e ka hasur këtë problem
  • 7 parje
  • Përgjigjja më e re nga Naresh Gunda

more options

Loading external website in an iframe is getting blocked because of x-frame-options in response headers. I want to detect what is the value for x-frame-options and based on that value i want to show an alert to the user. How can we detect/extract x-frame-options from the response headers for the given url even if it has redirects?

Loading external website in an iframe is getting blocked because of '''x-frame-options''' in response headers. I want to detect what is the value for '''x-frame-options''' and based on that value i want to show an alert to the user. '''How can we detect/extract x-frame-options from the response headers''' for the given url even if it has redirects?

Ndryshuar nga Naresh Gunda

Krejt Përgjigjet (2)

more options

I'm not sure under what conditions you want to check this like you have a website that allows to embed such content or you want to do this locally.

There is an extension for Firefox that allows this.

more options

I want to do it programmatically as i don't want end user to go to settings and disable enhanced tracking protection or installing some extensions in order to work with embeded content. So if i'm able to detect the x-frame-options i can ask user to launch the same url in new window by providing a button(Latest Firefox is doing similarly but i want to handle it in our website so that solution will work across the browsers).

Attached firefox implementation screenshot for reference.

Ndryshuar nga Naresh Gunda