允许同源

add_header X-Frame-Options SAMEORIGIN;

允许泛域名

add_header X-Frame-Options "allow-from https://*.xxx.cn/";