How to disable ‘X-Frame-Options’ response header in Spring Security?

If you’re using Java configs instead of XML configs, put this in your WebSecurityConfigurerAdapter.configure(HttpSecurity http) method:

http.headers().frameOptions().disable();

Leave a Comment