django - Nginx server edit to allow iframe from any site -


i've done curl -i www.site.com , result

http/1.1 200 ok server: nginx date: mon, 21 sep 2015 13:16:11 gmt content-type: text/html; charset=utf-8 content-length: 103555 connection: keep-alive vary: accept-encoding vary: cookie x-frame-options: sameorigin set-cookie: csrftoken=hkixbllqggxlt1fgrbfbm3af3g1cpxxp; expires=mon,    19-sep-2016                                                                                         13:16:11 gmt; max-age=31449600; path=/ 

i need edit server x-frame-options: allow all. delicate , such did not go around testing without being sure. appreciate guidance on this.

there clickjacking prevention in middleware once removed worked perfectly.

middleware_classes = (     #'django.middleware.cache.updatecachemiddleware',     #'django.middleware.gzip.gzipmiddleware',     'django.middleware.common.commonmiddleware',     'django.contrib.sessions.middleware.sessionmiddleware',     'django.middleware.csrf.csrfviewmiddleware',     'django.contrib.auth.middleware.authenticationmiddleware',     'django.contrib.messages.middleware.messagemiddleware',     #'django.middleware.clickjacking.xframeoptionsmiddleware',     'django.contrib.redirects.middleware.redirectfallbackmiddleware',     #'django.middleware.cache.fetchfromcachemiddleware',     'minidetector.middleware',     'mobileesp.middleware.mobiledetectionmiddleware',     #'django_mobileesp.middleware.useragentdetectionmiddleware', ) 

Comments

Popular posts from this blog

java - Date formats difference between yyyy-MM-dd'T'HH:mm:ss and yyyy-MM-dd'T'HH:mm:ssXXX -

c# - Get rid of xmlns attribute when adding node to existing xml -