App must set security headers to protect against clickjacking

App must set security headers to protect against clickjacking

Crystallist
Shopify Partner
2 0 0

<p><span>Your app must set the proper&nbsp;</span><a class="" href="https://shopify.dev/apps/store/security/iframe-protection" target="_blank" rel="noopener">frame-ancestors content security policy directive</a><span>&nbsp;to avoid clickjacking attacks. The 'content-security-policy' header should set&nbsp;</span><strong>frame-ancestors</strong><span>&nbsp;</span><strong>https://[shop].myshopify.com <a href="https://admin.shopify.com" target="_blank" rel="noopener">https://admin.shopify.com</a></strong><span>, where&nbsp;</span><strong>[shop]</strong><span>&nbsp;is the shop domain the app is embedded on.</span></p>

Replies 0 (0)