# X-frame-options not taking over docker container labels

**URL:** <https://community.traefik.io/t/x-frame-options-not-taking-over-docker-container-labels/17076>\
**Category:** Traefik v2\
**Tags:** docker\
**Created:** [January 10, 2023, 11:09am UTC](https://community.traefik.io/t/x-frame-options-not-taking-over-docker-container-labels/17076 "2023-01-10T11:09:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![simonszu](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/simonszu/32/708_2.png) [@simonszu](https://community.traefik.io/u/simonszu)\
**Post date:** [January 10, 2023, 11:09am UTC](https://community.traefik.io/t/x-frame-options-not-taking-over-docker-container-labels/17076/1 "2023-01-10T11:09:08Z")

</div>

I am trying to get contents served via traefik displayed as an iframe. Therefore i set the `customFrameOptionsValue` label for the backend container, so that traefik sends the `x-frame-options` header.

This is my label setting for the specific upstream docker container:

```auto
      traefik.http.routers.homepage.rule: "Host(`www.{{ traefik_domain }}`)"
      traefik.http.routers.homepage.entrypoints: "https"
      traefik.http.routers.homepage.service: "homepage"
      traefik.http.routers.homepage.tls.certresolver: "le-tls"
      traefik.http.services.homepage.loadbalancer.server.port: "80"
      traefik.http.services.homepage.loadbalancer.passHostHeader: 'true'
      traefik.http.middlewares.homepage.headers.customFrameOptionsValue: "allow-from https://www.qrz.com/db/do1ttk https://www.qrz.com"
      traefik.http.middlewares.homepage.headers.contentSecurityPolicy: "frame-ancestors https://www.qrz.com/db/do1ttk https://www.qrz.com"

```

However, the content is not displayed in the target iframe, and when i look at the headers sent out via the Chrome Dev tools, i see that the `x-frame-options` header is still set to `SAMEORIGIN`.

What am i missing here?

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [January 10, 2023, 11:55am UTC](https://community.traefik.io/t/x-frame-options-not-taking-over-docker-container-labels/17076/2 "2023-01-10T11:55:43Z")

</div>

You must assign your middleware to your router, see [docs with example](https://doc.traefik.io/traefik/middlewares/overview/#configuration-example).

---

<div class="post-metadata">

**Author:** ![simonszu](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/simonszu/32/708_2.png) [@simonszu](https://community.traefik.io/u/simonszu)\
**Post date:** [January 10, 2023, 1:25pm UTC](https://community.traefik.io/t/x-frame-options-not-taking-over-docker-container-labels/17076/3 "2023-01-10T13:25:56Z")

</div>

OK, thanks for pointing that out. I added the following label to the list:  
`traefik.http.routers.homepage.middlewares: homepage@docker`

Now, the traefik web frontend shows the header middleware in the router definition:

 ![middlewares](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/f/fcb4c268a090ece7a3d45ae44df57757c4249413.png)

The iframe is now loading, because of the contentSecurityPolicy option. However, the x-frame-options still shows SAMEORIGIN despite the customFrameOptionsValue is set. Well, i guess, maybe my Chrome is too new, then 😉
