From 37718246ad34669f9f862d4c7fb43dd94e3e50b4 Mon Sep 17 00:00:00 2001 From: Claire Date: Tue, 23 May 2023 14:27:17 +0200 Subject: [PATCH] Remove invalid X-Frame-Options: ALLOWALL (#25070) --- app/controllers/media_controller.rb | 2 +- app/controllers/statuses_controller.rb | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/app/controllers/media_controller.rb b/app/controllers/media_controller.rb index ee82625a03e9f9..42e32ce2aee259 100644 --- a/app/controllers/media_controller.rb +++ b/app/controllers/media_controller.rb @@ -46,6 +46,6 @@ def check_playable end def allow_iframing - response.headers['X-Frame-Options'] = 'ALLOWALL' + response.headers.delete('X-Frame-Options') end end diff --git a/app/controllers/statuses_controller.rb b/app/controllers/statuses_controller.rb index c52170d08188ac..3d1b74489b549c 100644 --- a/app/controllers/statuses_controller.rb +++ b/app/controllers/statuses_controller.rb @@ -48,7 +48,7 @@ def embed return not_found if @status.hidden? || @status.reblog? expires_in 180, public: true - response.headers['X-Frame-Options'] = 'ALLOWALL' + response.headers.delete('X-Frame-Options') render layout: 'embedded' end