【发布时间】:2015-08-24 05:26:27
【问题描述】:
我试图在 Nginx 中设置 ALLOWED-FROM 但到目前为止我尝试的所有设置都导致以下 Chrome 错误:
Invalid 'X-Frame-Options' header encountered when loading 'https://domain.com/#/register': 'ALLOW-FROM domain.com' is not a recognized directive. The header will be ignored.
我尝试的这些选项是:(也尝试使用带有 https:// 前缀的 FQDN)
add_header X-Frame-Options "Allow-From domain.com";
add_header X-Frame-Options "ALLOW-FROM domain.com";
add_header X-Frame-Options "ALLOW-FROM: domain.com";
add_header X-Frame-Options "Allow-From: domain.com";
add_header X-Frame-Options ALLOW-FROM "domain.com";
add_header X-Frame-Options ALLOW-FROM domain.com;
【问题讨论】:
-
Chrome 不支持
allow-from。 developer.mozilla.org/en-US/docs/Web/HTTP/…
标签: nginx cross-domain content-security-policy x-frame-options