The HTTP header ________ helps in specifying which domains are allowed to embed a page, thus mitigating some types of XSS attacks.

  • Access-Control-Allow-Origin
  • Content-Type
  • Referrer-Policy
  • X-Frame-Options
The 'Access-Control-Allow-Origin' header controls which domains can embed the page, reducing the risk of XSS attacks through malicious embedding.
Add your answer
Loading...

Leave a comment

Your email address will not be published. Required fields are marked *