
# BEGIN WPForms
# The directives (lines) between "BEGIN WPForms" and "END WPForms" are
# dynamically generated, and should only be modified via WordPress filters.
# Any changes to the directives between these markers will be overwritten.
<IfModule mod_headers.c>
  Header set Content-Security-Policy "frame-ancestors 'self' *; frame-src 'self' *; child-src 'self' *"
  Header set Access-Control-Allow-Origin "*"
  Header set Access-Control-Allow-Credentials "true"
</IfModule>
# Disable access for any file in the cache dir.
# Apache 2.2
<IfModule !authz_core_module>
	Deny from all
</IfModule>

# Apache 2.4+
<IfModule authz_core_module>
	Require all denied
</IfModule>
# END WPForms