[Marten Deinum](https://jira.spring.io/secure/ViewProfile.jspa?name=mdeinum) (Migrated from [SEC-2098](https://jira.spring.io/browse/SEC-2098?redirect=false)) said: Although a clickjacking filter is simple to implement it would be nice if spring security provided one out of the box with an easy way of configuring. <sec:clickjack mode="deny" /> or <sec:clickjack mode="sameorigin" />