1. headers http header: x-frame-options: allow-from