Thats intended behaviour if you didnt install it globally
Thats intended behaviour if you didnt install it globally



allow-from is deprecated and ignored by all modern browsersx-frame-options, and instead setting a CSP, with frame-ancestors, and more explicitly specifying where you want it embedded: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestors

allow-fromx-frame-optionsframe-ancestors