From 1c1427520dbba454fd8e31514f39dcaf995c2a17 Mon Sep 17 00:00:00 2001 From: Marcus Efraimsson Date: Mon, 6 May 2019 09:56:23 +0200 Subject: [PATCH] Security: Add new setting allow_embedding (#16853) When allow_embedding is false (default) the Grafana backend will set the http header `X-Frame-Options: deny` in all responses to non-static content which will instruct browser to not allow Grafana to be embedded in ``, `