
Last activity: 17 Jan 2024 9:06 EST
Set X-Frame-Options header to DENY or SAMEORIGIN page by page
To protect against Clickjacking, any page that contains forms which require a user to enter sensitive information, Veracode recommends using the X-Frame-Options header set to either DENY or SAMEORIGIN. Currently this value is set at a CSP level or in DSS (as a custom header) that applies to whole application and not set page by page.
We would like to know if the above recommendation from Veracode can be implemented and if not, why and whether anything can be done to compensate.