headers->set('X-Frame-Options', 'SAMEORIGIN', false); return $response; } }