Content-Security-Policies and X-Frame-Options

I am trying to restrict iframes from app app to certain domains. Bubble only allows for block all, self and allowall.

I created a rule in cloudflare but it doesnt override bubble’s reponse header.

Any ideas?

1 Like