......@@ -16,6 +16,7 @@ class RemoveXFrameOptionsSubscriber implements EventSubscriberInterface {
public function RemoveXFrameOptions(FilterResponseEvent $event) {
$response = $event->getResponse();
$response->headers->set('X-Frame-Options', 'ALLOW-FROM');
$response->headers->set('Content-Security-Policy', 'frame-ancestors');
