Files
bambuddy/backend
maziggy f1483f525d fix: relax X-Frame-Options to SAMEORIGIN so same-origin iframes load
The security-headers middleware added in 0.2.3b4 set X-Frame-Options: DENY
  on every response, which blocked the Spoolman page iframe when Spoolman
  was served from the same host as Bambuddy via a reverse proxy. Relaxed
  to SAMEORIGIN — same-origin embedding works again, cross-origin
  clickjacking protection is preserved.
2026-04-13 09:18:35 +02:00
..