Is it possible to use iFrames to embed other asset canisters?

Hey there @bjoern

You’ve once posted this message:

From which it seems like there was no initial intent to set the X-Frame-Origin header to Deny and this is some kind of misunderstanding within the team. Did you guys figured it out? Could you please ping someone who can elaborate on that?

It looks like clickjacking can still be performed, judging by this:

Thanks in advance!

1 Like