From 3249a227d63405e9f2af2c872a5afca2ee41d810 Mon Sep 17 00:00:00 2001 From: Hamza-Ayed Date: Mon, 4 May 2026 20:12:58 +0300 Subject: [PATCH] Update: 2026-05-04 20:12:58 --- app/bootstrap/init.php | 2 +- public/shell.php | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/app/bootstrap/init.php b/app/bootstrap/init.php index dbe0414..643a0e3 100644 --- a/app/bootstrap/init.php +++ b/app/bootstrap/init.php @@ -57,7 +57,7 @@ if ($_SERVER['REQUEST_METHOD'] === 'OPTIONS') { // 5. Security Headers header("X-Content-Type-Options: nosniff"); -header("X-Frame-Options: DENY"); +header("X-Frame-Options: SAMEORIGIN"); header("X-XSS-Protection: 1; mode=block"); header("Referrer-Policy: strict-origin-when-cross-origin"); header("Strict-Transport-Security: max-age=31536000; includeSubDomains"); // I1 Fix: HSTS diff --git a/public/shell.php b/public/shell.php index 5d8f75d..3dabe0c 100644 --- a/public/shell.php +++ b/public/shell.php @@ -397,7 +397,7 @@
لا يوجد ملف مرفق