<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>IBM BAW Tips Q&amp;A - Recent questions tagged headers</title>
<link>https://bpm.tips/tag/headers</link>
<description>Powered by Question2Answer</description>
<item>
<title>How do I secure coach views and REST calls against a strict Content Security Policy and clickjacking headers on BAW?</title>
<link>https://bpm.tips/3441/how-do-i-secure-coach-views-and-rest-calls-against-a-strict-content-security-policy-and-clickjacking-headers-on-baw</link>
<description>Security asked us to add Content-Security-Policy and X-Frame-Options headers on the BAW web tier. After that, coaches with inline scripts broke and the portal iframe stopped rendering. What is compatible with coaches and what needs code changes?</description>
<guid isPermaLink="true">https://bpm.tips/3441/how-do-i-secure-coach-views-and-rest-calls-against-a-strict-content-security-policy-and-clickjacking-headers-on-baw</guid>
<pubDate>Sun, 06 Sep 2026 13:39:49 +0000</pubDate>
</item>
</channel>
</rss>