We have a based java restapi webapplication , i am trying to pentest it and i went through the owasp security sheet for restapi :
https://www.owasp.org/index.php/REST_Security_Cheat_Sheet#Security_headers
As owasp recommends, "Additionally the client should send an X-Frame-Options: deny to protect against drag'n drop clickjacking attacks in older browsers. ", however, as i know, the server usually send this x-frame-options, not the client, is it a typo failure from owasp ? in addition, with rest api request, how could clickjacking be exploited as restapi calls are not seen in the browser !?