@@ -1008,7 +1008,15 @@ function top_httphead($contenttype='text/html')
// Security options
header("X-Content-Type-Options: nosniff");// With the nosniff option, if the server says the content is text/html, the browser will render it as text/html (note that most browsers now force this option to on)
header("X-Frame-Options: SAMEORIGIN");// Frames allowed only if on same domain (stop some XSS attacks)