Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Set Xframe options to prevent embedding third-party websites

Configure this property to prevent the content of a web-application from being embedded in a third-party site.

If the com.glide.cs.embed.xframe_options system property is not set to the recommended value of DENY or SAMEORIGIN, then content of the web application could be embedded in a third-party site using an ALLOW-FROM URI.

Ensure the property com.glide.cs.embed.xframe_options is set to DENY or SAMEORIGIN.

More information

AttributeDescription
Configuration namecom.glide.cs.embed.xframe_options
Configuration typeSystem Properties \(/sys\_properties\_list.do\)
Data typeString
Recommended value`DENY` or `SAMEORIGIN`
Default value<none>
Fallback value<empty>
CategoryConfiguration
Security risk- Severity score: 3.1 - CVSS score: Low - Security risk details: Allowing untrusted third-party sites could enable attacks such as clickjacking.
Dependencies and prerequisitesNone

Parent Topic:Configuration