
在我的网站上,
如何从X-Frame-Options: SAMEORIGIN核心响应中删除asp.net头。
我已经尝试过的
string MyAllowSpecificOrigins = "_myAllowSpecificOrigins";
services.AddCors(options =>
{
options.AddPolicy(MyAllowSpecificOrigins,
builder =>
{
builder.WithOrigins("http://www.example.org/",
"https://www.example.org/");
});
});
app.UseCors(MyAllowSpecificOrigins);services.AddAntiforgery(x => x.SuppressXFrameOptionsHeader = true);
<remove name="X-Frame-Options"/>发布于 2020-03-08 07:31:50
初始化abp框架如下:
app.UseAbp(options =>
{
options.UseSecurityHeaders = false;
}); // Initializes ABP framework.https://stackoverflow.com/questions/60584764
复制相似问题