mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 11:12:35 +02:00
The security-headers middleware added in 0.2.3b4 set X-Frame-Options: DENY on every response, which blocked the Spoolman page iframe when Spoolman was served from the same host as Bambuddy via a reverse proxy. Relaxed to SAMEORIGIN — same-origin embedding works again, cross-origin clickjacking protection is preserved.