- 'always unset "X-Powered-By"'
- 'set X-Content-Type-Options: nosniff'
- 'set X-XSS-Protection: "1; mode=block"'
- - 'set X-Frame-Options: DENY'
+ - 'set X-Frame-Options: ALLOW-FROM https://dev-cms01-meine-krankenkasse-de.pixelpark.net'
- "set Content-Security-Policy: \"default-src 'self'; img-src 'self' webstats.pixelpark.com data:; font-src 'self'; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' webstats.pixelpark.com; child-src 'self'; frame-ancestors 'self'\""
- "set X-Content-Security-Policy: \"default-src 'self'; img-src 'self' webstats.pixelpark.com data:; font-src 'self'; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' webstats.pixelpark.com; child-src 'self'; frame-ancestors 'self'\""
headers_ssl: