We are using CAS 6.2 for our deployment. We are using Authentication using OIDC . Due to different domains we disable x-frame options with httpHeaderEnableXFrameOpti