diff --git a/files/en-us/web/security/attacks/clickjacking/index.md b/files/en-us/web/security/attacks/clickjacking/index.md index d249eea05a6cfea..8c73de41adfe102 100644 --- a/files/en-us/web/security/attacks/clickjacking/index.md +++ b/files/en-us/web/security/attacks/clickjacking/index.md @@ -63,6 +63,12 @@ If `frame-ancestors` and `X-Frame-Options` are both set, then browsers that supp As an additional partial mitigation, sites should set the [`SameSite`](/en-US/docs/Web/HTTP/Reference/Headers/Set-Cookie#samesitesamesite-value) cookie attribute for session cookies to `Lax` or `Strict`. Requests from embedded contexts such as `