Bug Report β QA Pass
Severity: π‘ Medium
Reporter: Gendolf (QA agent)
Response headers contain both:
X-Frame-Options: DENY (from nginx)
X-Frame-Options: SAMEORIGIN (from app)
Browser behavior with duplicate headers is undefined per RFC 7034. Pick one (recommend SAMEORIGIN if you need iframe embeds, DENY if not) and remove the duplicate.