App reviews, troubleshooting, and recommendations
Good day,
Our application submission does not go through the requirements that must be met before initial screening. The only comment we receive is for the security headers set to protect against clickjacking.
What we do not understand is that as per the documentation Setting up Iframe protection, we need to check the Content-Security-Policy and the Request URL from the response headers and we believe we are complying with the requirements.
CSP with frame-ancestors
Request URL
You need to setting up iframe Protection in every page of your app.
Hi, thank you for your answer,
We made sure that the Iframe Protection is set up on every page of our app, as long as the 'shop' params is provided.
In Canada, payment processors, like those that provide payment processing services t...
By Jacqui Mar 14, 2025Unlock the potential of marketing on your business growth with Shopify Academy's late...
By Shopify Mar 12, 2025Learn how to increase conversion rates in every stage of the customer journey by enroll...
By Shopify Mar 5, 2025