<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTP Response Headers and plugin in QlikView</title>
    <link>https://community.qlik.com/t5/QlikView/HTTP-Response-Headers-and-plugin/m-p/542568#M1302487</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have IIS configured to display the qvplugin and it's working fine, recently I noticed that the X-Frame-Options in the HTTP Response Headers was set to ALLOW, Now I'm asked to change its value to SAMEORIGIN due to security reasons. When doing this, the plugin is not opened as expected, instead I get thisn error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;STRONG style="font-size: 14px; color: #000000; font-family: Arial, 'Liberation Sans', 'DejaVu Sans', sans-serif;"&gt;"To help protect the security of information you enter into this website, the publisher of this content does not allow it to be displayed in a frame."&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why is this happening? I think SAMEORIGIN should be enough. Could someone give me some more explanation in this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Jan 2026 18:19:17 GMT</pubDate>
    <dc:creator />
    <dc:date>2026-01-26T18:19:17Z</dc:date>
    <item>
      <title>HTTP Response Headers and plugin</title>
      <link>https://community.qlik.com/t5/QlikView/HTTP-Response-Headers-and-plugin/m-p/542568#M1302487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have IIS configured to display the qvplugin and it's working fine, recently I noticed that the X-Frame-Options in the HTTP Response Headers was set to ALLOW, Now I'm asked to change its value to SAMEORIGIN due to security reasons. When doing this, the plugin is not opened as expected, instead I get thisn error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;STRONG style="font-size: 14px; color: #000000; font-family: Arial, 'Liberation Sans', 'DejaVu Sans', sans-serif;"&gt;"To help protect the security of information you enter into this website, the publisher of this content does not allow it to be displayed in a frame."&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why is this happening? I think SAMEORIGIN should be enough. Could someone give me some more explanation in this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2026 18:19:17 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/HTTP-Response-Headers-and-plugin/m-p/542568#M1302487</guid>
      <dc:creator />
      <dc:date>2026-01-26T18:19:17Z</dc:date>
    </item>
  </channel>
</rss>

