2012年10月10日 星期三

js load google into an iframe

Reference
Google and Facebook are using a X-Frame-Options in the HTTP response header to avoid the content being loaded in a iFrame.

The X-Frame-Options HTTP response header can be used to indicate whether or not a browser should be allowed to render a page in a or . Sites can use this to avoid clickjacking attacks, by ensuring that their content is not embedded into other sites.


Source: Mozilla Developer Network - The X-Frame-Options response header

I don't think it is possible for you to override this setting.

Solution


  1. Browse to google page.
  2. Save the Google web page.
  3. Remove the X-Frame-Options tag.
  4. Now, You can load the modified google web page into an iframe.

沒有留言: