1. headers http header: x-frame-options: sameorigin