Files
coder/coderd/httpmw
Jakub Domeracki 5f343bc337 fix(coderd): backport frame-ancestors CSP fixes to 2.32 (#24474, #24529) (#24806)
Cherry-pick backport of #24474 and #24529 to `release/2.32`.

- #24474: fix(coderd): add frame-ancestors CSP directive to prevent
clickjacking
- #24529: fix(coderd): omit frame-ancestors CSP for embed routes

Both commits cherry-picked cleanly with no conflicts.

> Generated by Coder Agents
2026-05-13 15:16:48 -04:00
..