Thanks I will check on this when I can, right now I dont have access to my test platform.
As I recall, I do have "Referrer-Policy" set to "no-referrer" and "frame-ancestors 'self'" should count for X-Frame-Options (though I have it in my config as well). However I think my score was not correct. I got 80/100 with -20 from CSP, +5 "Referrer-Policy" and +5 "frame-ancestors 'self'" so maybe it capped me at 80 points due to CSP. -- Sent from: http://apache-guacamole-general-user-mailing-list.2363388.n4.nabble.com/
