My App keeps rejecting due to App must set security headers to protect against clickjacking

My App keeps rejecting due to App must set security headers to protect against clickjacking

HemaBadgali
New Member
4 0 0

Requirements that must be met before initial screening

  1. App must set security headers to protect against clickjacking.
    Your app must set the proper frame-ancestors content security policy directive to avoid clickjacking attacks. The 'content-security-policy' header should set frame-ancestors https://[shop].myshopify.com https://admin.shopify.com, where [shop] is the shop domain the app is embedded on.
Replies 0 (0)