# 임베드 컨트롤러에서 잘못된 응답 헤더가 설정되고 있습니다

**URL:** https://meta.discourse.org/t/and-invalid-response-header-is-being-set-from-embed-controller/183178
**Category:** Support
**Created:** [3월 14, 2021, 2:55오전 UTC](https://meta.discourse.org/t/and-invalid-response-header-is-being-set-from-embed-controller/183178 "2021-03-14T02:55:36Z")
**Posts on this page:** 1
**Showing post:** 4

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [3월 23, 2021, 12:17오전 UTC](https://meta.discourse.org/t/and-invalid-response-header-is-being-set-from-embed-controller/183178/4 "2021-03-23T00:17:03Z")

</div>

이제 수정되었습니다:

> [@Mitigate XSS Attacks with Content Security Policy](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243/37?u=falco):
>
> We just landed support for CSP frame-ancestors directive. It’s disabled by default for now behind the content security policy frame ancestors site setting. You can add domains to the list using via /admin/customize/embedding as always. This directive will be enabled by default in the next release cycle.

---

_[View the full topic](https://meta.discourse.org/t/and-invalid-response-header-is-being-set-from-embed-controller/183178)._
