My Jitsi Appimage is running in a normal xubuntu vm but all it’s traffic is routed via whonix gateway cli vm. I don’t think whonix adds anything to a http request but I’m not sure.
We (meet.jit.si) don’t set X-Frame-Options: sameorigin because that would prevent using iframes, which we support.
If things work when you don’t enable whonix then there is your answer. Some security things think X-Frame-Options other than sameorigin is unsafe, but it isn’t if your intention is to be embedded in the first place.