给您的网站添加X-Frame-Options响应头,赋值有如下三种:
- DENY:无论如何不在框架中显示;
- SAMEORIGIN:仅在同源域名下的框架中显示;
- ALLOW-FROM uri:仅在指定域名下的框架中显示。
具体配置:在tomcat/conf/web.xml中配置下面代码:
web.xml搜索 httpHeaderSecurity,首先放开 httpHeaderSecurity的注释
然后添加部分语句,下面是完整配置:
<filter>
<filter-name>httpHeaderSecurity</filter-name>
<filter-class>org.apache.catalina.filters.HttpHeaderSecurityFilter</filter-class>
<init-param>
<param-name>antiClickJackingEnabled</param-name>
<param-value>true</param-value>
</init-param>
<init-param>
<param-name>antiClickJackingOption</param-name>
<param-value>ALLOW-FROM</param-value>
</init-param>
<init-param>
<param-name>antiClickJackingUri</param-name>
<param-value>https://baidu.com/</param-value>
</init-param>
<async-supported>true</async-supported>
</filter>
<filter-mapping>
<filter-name>httpHeaderSecurity</filter-name>
<url-pattern>/*</url-pattern>
<dispatcher>REQUEST</dispatcher>
</filter-mapping>
重启tomcat服务即可