You put it in the config/application.rb
file. Open up the file and you should be able to see where to add it.
I'm using
config.action_dispatch.default_headers.merge!({'X-Frame-Options' => 'ALLOWALL'})
so that the other default headers are preserved