Frame ancestors directive or X-Frame Options to protect against ClickJacking attacks
under review
If you expect the page to be framed only by pages on your server (e.g. it's part of a FRAMESET) then you'll want to use SAMEORIGIN, otherwise if you never expect the page to be framed, you should use DENY. Alternatively consider implementing Content Security Policy's frame ancestors directive.
under review
Thank you for bringing this to our attention! Our Dev team will check it and get back to you.