缺少X-Frame-Options头的解决办法在tomcat下的conf里的web.xml中增加以下过滤器httpHeaderSecurityorg.apache.catalina.filters.HttpHeaderSecurityFilterantiClickJackingEnabledtrueantiClickJackingOptionSAMEORIGINtruehttpHeaderSecurity/*