mirror of
https://github.com/coder/coder.git
synced 2026-06-04 05:28:20 +00:00
49be5f31d3
Cherry-pick backport of #24474 and #24529 to `release/2.31`. - #24474: fix(coderd): add frame-ancestors CSP directive to prevent clickjacking - #24529: fix(coderd): omit frame-ancestors CSP for embed routes Both commits cherry-picked cleanly with no conflicts. > Generated by Coder Agents