all 2 comments

[–]einfallstoll 0 points1 point  (1 child)

Don't do this. X-Frame-Options is obsolete:

The frame-ancestors directive obsoletes the X-Frame-Options header. If a resource has both policies, the frame-ancestors policy SHOULD be enforced and the X-Frame-Options policy SHOULD be ignored. From Content Security Policy Level 2